← Vulnerability feed

Vulnerability record · CVE-2008-5109 · published 25 November 2008

CVE-2008-5109: Adobe flash media server vulnerability

Adobe · Flash Media Server

The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.

5.0 CVSS 2.0 Medium EPSS 2.3% · top 17.3% CWE-16 · CWE-16
5.0CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5109 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-3635Adobe flash media server code injection vulnerabilityAdobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to execute arbitrary code via unspecif…EPSS 5.9%10.0CVE-2010-2217Adobe flash media server code injection vulnerabilityAdobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to execute arbitrary code via unspecified vectors, related to a…EPSS 4.5%10.0CVE-2009-3792Adobe flash media server path traversal vulnerabilityDirectory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL files via unspecified vectors.EPSS 4.1%7.5CVE-2009-3791Adobe flash media server uncontrolled resource consumption vulnerabilityUnspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion) via unkn…EPSS 2.6%7.5CVE-2009-1365Adobe flash media server vulnerabilityUnspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash …EPSS 3.3%5.0CVE-2011-2132Adobe flash media server memory buffer overflow vulnerabilityAdobe Flash Media Server (FMS) before 3.5.7, and 4.x before 4.0.3, allows attackers to cause a denial of service (memory corruption) via unspecified …EPSS 8.5%5.0CVE-2011-0612Adobe flash media server vulnerabilityAdobe Flash Media Server (FMS) before 3.5.6, and 4.x before 4.0.2, allows remote attackers to cause a denial of service (XML data corruption) via uns…EPSS 2.2%5.0CVE-2010-3633Adobe flash media server vulnerabilityMemory leak in Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to cause a denial of se…EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2008-5109), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.