{"api_version":"1","generated_at":"2026-07-23T08:55:09+00:00","cve":"CVE-2009-1365","urls":{"html":"https://cve.report/CVE-2009-1365","api":"https://cve.report/api/cve/CVE-2009-1365.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1365","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1365"},"summary":{"title":"CVE-2009-1365","description":"Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-05-01 17:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.adobe.com/support/security/bulletins/apsb09-05.html","name":"http://www.adobe.com/support/security/bulletins/apsb09-05.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe - Security Advisories : APSB09-05 - Updates available to address Flash Media Server privilege escalation issue","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/1234","name":"http://www.vupen.com/english/advisories/2009/1234","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"inode/x-empty","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34790","name":"http://www.securityfocus.com/bid/34790","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Adobe Flash Media Server Unspecified RPC Call Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/34878","name":"http://secunia.com/advisories/34878","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe Flash Media Server RPC Security Bypass Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022148","name":"http://www.securitytracker.com/id?1022148","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe Flash Media Server Bug Lets Remote Users Execute Remote Procedures - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1365","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1365","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"2.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"2.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"2.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"2.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"3.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"3.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"3.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"3.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1365","vulnerable":"1","versionEndIncluding":"3.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:13:25.221Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"34790","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34790"},{"name":"34878","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34878"},{"name":"ADV-2009-1234","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1234"},{"name":"1022148","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022148"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb09-05.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-04-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-05-14T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"34790","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34790"},{"name":"34878","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34878"},{"name":"ADV-2009-1234","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1234"},{"name":"1022148","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022148"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb09-05.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1365","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"34790","refsource":"BID","url":"http://www.securityfocus.com/bid/34790"},{"name":"34878","refsource":"SECUNIA","url":"http://secunia.com/advisories/34878"},{"name":"ADV-2009-1234","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1234"},{"name":"1022148","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1022148"},{"name":"http://www.adobe.com/support/security/bulletins/apsb09-05.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb09-05.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1365","datePublished":"2009-05-01T17:00:00.000Z","dateReserved":"2009-04-22T00:00:00.000Z","dateUpdated":"2024-08-07T05:13:25.221Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-05-01 17:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0.3","matchCriteriaId":"EAF97B08-1802-4850-893A-C541E6BFB6A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"73544702-D995-43BA-92CB-01ED3642D22E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:2.0.2:*:*:*:*:*:*:*","matchCriteriaId":"7C5602CE-0860-46EC-9D31-13A83A81476A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:2.0.3:*:*:*:*:*:*:*","matchCriteriaId":"CE2057CB-905A-4E81-A9EB-898105B2DF0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:2.0.4:*:*:*:*:*:*:*","matchCriteriaId":"95E05CA6-B186-4213-A46F-C4E0458B2CA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:2.0.5:*:*:*:*:*:*:*","matchCriteriaId":"9F9D585C-DBD6-4E13-A8FF-E043EC162D9D"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:3.0:*:*:*:*:*:*:*","matchCriteriaId":"EE4A07B6-E5DA-4781-ABB3-DB2663E2A737"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:3.0.1:*:*:*:*:*:*:*","matchCriteriaId":"84681400-0CBD-41D1-94D0-B9045958793D"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:3.0.2:*:*:*:*:*:*:*","matchCriteriaId":"29A5E8DC-E664-4FAF-9ED9-7191433F01E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:3.5:*:*:*:*:*:*:*","matchCriteriaId":"897B12DA-8749-44F7-AA1E-AB1F01BB205E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:3.5.1:*:*:*:*:*:*:*","matchCriteriaId":"8334A448-0DFF-4571-81BC-81ADEDBD9D7C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1365","Ordinal":"1","Title":"CVE-2009-1365","CVE":"CVE-2009-1365","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1365","Ordinal":"1","NoteData":"Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests.","Type":"Description","Title":"CVE-2009-1365"},{"CveYear":"2009","CveId":"1365","Ordinal":"2","NoteData":"2009-05-01","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1365","Ordinal":"3","NoteData":"2009-05-14","Type":"Other","Title":"Modified"}]}}}