<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#esx esx-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#ios ios-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#aix aix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2008-10-01T09:00:29.826-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:999" version="1">
      <metadata>
        <title>Hyperlink Object Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3086" source="CVE"/>
        <description>Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:41.883-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:50.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.560" test_ref="oval:org.mitre.oval:tst:114"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:998" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Xorg Privilege Escalation via Pixmaps Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>X</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2495"/>
        <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-12T01:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 9 (x86,Xorg) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 118908-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1337"/>
            <criterion comment="File Xorg exists" negate="false" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86,Xorg) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 118966-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1335"/>
            <criterion comment="File Xorg exists" negate="false" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="The Xorg X server is running" negate="false" test_ref="oval:org.mitre.oval:tst:1334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:997" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise Linux 3 Kernel Serial Link Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0461"/>
        <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.280-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:12.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kernel version is less than 2.4.21-15.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1342"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/proc/tty/driver/serial is world-readable" negate="false" test_ref="oval:org.mitre.oval:tst:1341"/>
          <criterion comment="/proc/tty/driver/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1340"/>
          <criterion comment="/proc/tty/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1339"/>
          <criterion comment="/proc/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1338"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:996" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Share Level Password Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <product>File and Print Sharing</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0979"/>
        <description>File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:32:00.000-04:00" comment="modified wft-337 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 98 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1345"/>
        <criterion comment="File %windir%\system\vserver.vxd version is less than 4.10.2001.0" negate="false" test_ref="oval:org.mitre.oval:tst:1344"/>
        <criterion comment="Patch 273991USA8.EXE Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1343"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:995" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0807"/>
        <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-18T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-02T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcproxy.dll is less than 5.0.2195.6904" negate="false" test_ref="oval:org.mitre.oval:tst:1346"/>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="COM Internet Services are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:994" version="1" class="vulnerability">
      <metadata>
        <title>CVS error_prog_name Double-free Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0416"/>
        <description>Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Red Hat Enterprise 3 is installed" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cvs rpm version prior to 1.11.2-24 is installed" test_ref="oval:org.mitre.oval:tst:1347"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:993" version="1" class="vulnerability">
      <metadata>
        <title>CVS Improper Handling of Malformed Entry Lines</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0414"/>
        <description>CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1347"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:992" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX Running on Itanium Platforms Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3295"/>
        <description>Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-31T12:19:00.000-04:00" comment="Updated reference to CVE-2005-3295.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.943-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.727-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.989-04:00">ACCEPTED</status_change>
            <modified comment="Updated for CVE-2005-3295" date="2008-09-09T10:39:00.374-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-09-09T10:42:43.389-04:00">INTERIM</status_change>
            <status_change date="2008-09-29T04:00:53.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX01233">
        <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:1350"/>
        <criteria negate="true" operator="OR" comment="Patch PHKL_33713 and PHKL_33714 are installed">
          <criterion comment="Patch PHKL_33713 is installed" test_ref="oval:org.mitre.oval:tst:1349"/>
          <criterion comment="Patch PHKL_33714 is installed" test_ref="oval:org.mitre.oval:tst:1348"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:991" version="2" class="vulnerability">
      <metadata>
        <title>Mutliple BO Vulnerabilities in MIT Kerberos 5</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>MIT Kerberos 5 (krb5)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523"/>
        <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:53.979-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:12.209-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="krb5-libs rpm version prior to 1.2.7-24 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1351"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:990" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v6.0 MHTML URL Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0380"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1353"/>
        <criterion comment="the version of inetcomm.dll is less than 6.00.2739.300" negate="false" test_ref="oval:org.mitre.oval:tst:1352"/>
        <criterion comment="the patch kb837009 is installed (installed components key)" negate="true" test_ref="oval:org.mitre.oval:tst:1512"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:99" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0 Content Disposition/Type Arbitrary Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0193"/>
        <description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-03-07T05:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:41.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2716.2200" negate="false" test_ref="oval:org.mitre.oval:tst:3086"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:989" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express 6,SP1 News Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1213"/>
        <description>Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 6 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1506" negate="false" test_ref="oval:org.mitre.oval:tst:1354"/>
        <criterion comment="Patch KB897715 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2853"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:988" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal MMSE Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0507"/>
        <description>Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:987" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal SPNEGO Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0506" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0506"/>
        <description>The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:986" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal AIM Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0505" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0505"/>
        <description>The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:985" version="1" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Call Memory Corruption (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1359"/>
        <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:984" version="2" class="vulnerability">
      <metadata>
        <title>Racoon Denial of Service via Large Length Field</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0403" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0403"/>
        <description>Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:52.316-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:12.021-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:983" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP IIS Out of Process Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0869"/>
        <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:1356 to use obj:496 was introduced to properly look for w3svc.dll in System32/inetsrv." date="2007-07-18T12:59:00.316-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:02:43.455-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.863-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS 5.1 Minor Version" negate="false" test_ref="oval:org.mitre.oval:tst:1357"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" negate="false" test_ref="oval:org.mitre.oval:tst:1356"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:982" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal Denial of Service via SIP Messages</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0504"/>
        <description>Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:980" version="1" class="vulnerability">
      <metadata>
        <title>NTLM Authentication BO in Squid Web Proxy Cache</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0541"/>
        <description>Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="squid version is less than 2.5.STABLE3-6.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1361"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1360"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:98" version="1" class="vulnerability">
      <metadata>
        <title>Gopher Client Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0371"/>
        <description>Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" negate="false" test_ref="oval:org.mitre.oval:tst:2945"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Gopher Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:979" version="1" class="vulnerability">
      <metadata>
        <title>Utempter Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0233"/>
        <description>Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="utempter version is less than 0.5.5-1.3EL.0" negate="false" test_ref="oval:org.mitre.oval:tst:1366"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/sbin/utempter is executable">
            <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1365"/>
            <criteria operator="OR" comment="/usr/sbin/utempter is executable">
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1364"/>
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1363"/>
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1362"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:978" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Directory Traversal Vulnerabilities in LHA</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0235"/>
        <description>Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="lha version is less than 1.14i-10.2" negate="false" test_ref="oval:org.mitre.oval:tst:1370"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/lha is executable">
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1369"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1368"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1367"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:977" version="1" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in LHA get_header Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0234"/>
        <description>Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="lha version is less than 1.14i-10.2" negate="false" test_ref="oval:org.mitre.oval:tst:1370"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/lha is executable">
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1369"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1368"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1367"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:976" version="1" class="vulnerability">
      <metadata>
        <title>tcpdump Identification Payload in ISAKMP Packets Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0184"/>
        <description>Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1374"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1373"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1372"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1371"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:975" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL do_change_cipher_spec Function Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.326-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:974" version="3" class="vulnerability">
      <metadata>
        <title>IE Frame Domain Verification Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0027"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-20T04:04:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" negate="false" test_ref="oval:org.mitre.oval:tst:1451"/>
        <criterion comment="Patch Q316059.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1458"/>
        <criterion comment="Patch Q319282 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1457"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:972" version="1" class="vulnerability">
      <metadata>
        <title>tcpdump Delete Payload in ISAKMP Packets Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0183"/>
        <description>TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1374"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1373"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1372"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1371"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:971" version="2" class="vulnerability">
      <metadata>
        <title>libpng Malformed PNG Image Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0421"/>
        <description>The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:34.590-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="libpng/libpng-devel is less than 1.2.2-21 or libpng10/libpng-devel less than 1.0.13 is installed">
          <criterion comment="libpng version is less than 1.2.2-21" negate="false" test_ref="oval:org.mitre.oval:tst:1378"/>
          <criterion comment="libpng-devel version is less than 1.2.2-21" negate="false" test_ref="oval:org.mitre.oval:tst:1377"/>
          <criterion comment="libpng10 version is less than 1.0.13-12" negate="false" test_ref="oval:org.mitre.oval:tst:1376"/>
          <criterion comment="libpng10-devel version is less than 1.0.13-12" negate="false" test_ref="oval:org.mitre.oval:tst:1375"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:970" version="2" class="vulnerability">
      <metadata>
        <title>CVS pserver BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0396"/>
        <description>Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.770-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-22" negate="false" test_ref="oval:org.mitre.oval:tst:1382"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:97" version="2" class="vulnerability">
      <metadata>
        <title>Solaris cachefsd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0084"/>
        <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Updated to add patch test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Added Solaris 9 and Solaris 9 patch test to the definition">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.350-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:45.666-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.147-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 110896-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2946"/>
          <criterion comment="Patch 114008-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3050"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:969" version="3" class="vulnerability">
      <metadata>
        <title>Windows NT COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0807"/>
        <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-18T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-02T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:02.359-05:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:01:01.739-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:55.494-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="Windows NT 4.0 Server or Terminal Server is installed">
            <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
            <criteria operator="OR" comment="Server or Terminal Server product option">
              <criteria operator="OR" comment="Windows NT server product option">
                <criterion comment="this is an NT Server (stand-alone)" test_ref="oval:org.mitre.oval:tst:2408"/>
                <criterion comment="this is an NT Server (domain controller)" test_ref="oval:org.mitre.oval:tst:3035"/>
              </criteria>
              <criterion comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of rpcproxy.dll exists on NT">
            <criteria operator="AND" comment="non Terminal Server and rpcproxy.dll is less than 4.0.1381.7255">
              <criterion negate="true" comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
              <criterion comment="the version of rpcproxy.dll is less than 4.0.1381.7255" test_ref="oval:org.mitre.oval:tst:1385"/>
            </criteria>
            <criteria operator="AND" comment="Terminal Server and rpcproxy.dll is less than 4.0.1381.33559">
              <criterion comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
              <criterion comment="the version of rpcproxy.dll is less than 4.0.1381.33559" test_ref="oval:org.mitre.oval:tst:1384"/>
            </criteria>
          </criteria>
          <criterion negate="true" comment="the patch kb828741 is installed" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="COM Internet Services are enabled" test_ref="oval:org.mitre.oval:tst:1383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:968" version="1" class="vulnerability">
      <metadata>
        <title>MS Jet Database Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Jet Database Engine</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0197" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0197"/>
        <description>Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="a vulnerable version of Microsoft Jet 4.0 is installed">
          <criteria operator="AND" comment="32-bit version of Windows and msjet40.dll is less than 4.0.8618.0">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="the version of msjet40.dll is less than 4.0.8618.0" negate="false" test_ref="oval:org.mitre.oval:tst:1388"/>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and wmsjet40.dll is less than 4.0.8618.0">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of wmsjet40.dll is less than 4.0.8618.0" negate="false" test_ref="oval:org.mitre.oval:tst:1387"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb837001 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:967" version="2" class="vulnerability">
      <metadata>
        <title>rsync Path Sanitation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0426"/>
        <description>rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:48.553-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.957-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="rsync version is less than 2.5.7-4.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:966" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Media Services ISAPI Logging Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0227"/>
        <description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" negate="false" test_ref="oval:org.mitre.oval:tst:1390"/>
        <criterion comment="Patch KB817772 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1439"/>
        <criterion comment="Patch KB822343 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:965" version="2" class="vulnerability">
      <metadata>
        <title>IE6 Script Execution Vulnerability (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1190"/>
        <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:17.686-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:02.006-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:964" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP H.323 Protocol Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>H.323</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0117"/>
        <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="a vulnerable version of h323.tsp exists">
          <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of h323.tsp exists">
            <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criteria operator="OR" comment="a vulnerable version of h323.tsp exists depending on service pack level">
              <criteria operator="AND" comment="no service pack is installed and h323.tsp is less than 5.1.2600.134">
                <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
                <criterion comment="the version of h323.tsp is less than 5.1.2600.134" test_ref="oval:org.mitre.oval:tst:1392"/>
              </criteria>
              <criteria operator="AND" comment="service pack 1 is installed and h323.tsp is less than 5.1.2600.1348">
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
                <criterion comment="the version of h323.tsp is less than 5.1.2600.1348" test_ref="oval:org.mitre.oval:tst:1391"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and h323.tsp is less than 5.1.2600.1348">
            <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of h323.tsp is less than 5.1.2600.1348" test_ref="oval:org.mitre.oval:tst:1391"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:963" version="2" class="vulnerability">
      <metadata>
        <title>IE File Upload Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0114"/>
        <description>The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:962" version="1" class="vulnerability">
      <metadata>
        <title>MDAC SQL-DMO Buffer Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Data Access Components 2.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0353"/>
        <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="DataAccess Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1394"/>
        <criterion comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" negate="false" test_ref="oval:org.mitre.oval:tst:1393"/>
        <criterion comment="Patch Q823718 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:961" version="2" class="vulnerability">
      <metadata>
        <title>MDAC SQL-DMO Buffer Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>MDAC 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0353"/>
        <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="split out the MDAC and file version tests from the compound test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" negate="false" test_ref="oval:org.mitre.oval:tst:1396"/>
        <criterion comment="Patch Q823718 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:960" version="1" class="vulnerability">
      <metadata>
        <title>Magick XWD Decoder DoS</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1739"/>
        <description>The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ImageMagick RPM earlier than 0:5.5.6-15" negate="false" test_ref="oval:org.mitre.oval:tst:1397"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:96" version="2" class="vulnerability">
      <metadata>
        <title>IE Cookie-based Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0078"/>
        <description>The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if cookies are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2715.400" negate="false" test_ref="oval:org.mitre.oval:tst:2952"/>
          <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="cookies are enabled">
            <criteria operator="AND" comment="current user settings are being used and cookies are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="persistent cookies that are stored on your computer are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2950"/>
              <criterion comment="persistent cookies that are stored on your computer are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2949"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and cookies are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="per-session cookies (not stored) are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2948"/>
              <criterion comment="per-session cookies (not stored) are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2947"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:959" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 WMF/EMF Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Enhanced Metafile (EMF)</product>
          <product>Windows Metafile (WMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0906"/>
        <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of mf3216.dll is less than 5.0.2195.6898" negate="false" test_ref="oval:org.mitre.oval:tst:1398"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:958" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP RPCSS Service DCOM Activation Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0116"/>
        <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:22:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="a vulnerable version of rpcss.dll exists on XP">
            <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of rpcss.dll exists">
              <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of rpcss.dll exists depending on service pack level">
                <criteria operator="AND" comment="no service pack is installed and rpcss.dll is less than 5.1.2600.135">
                  <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
                  <criterion comment="the version of rpcss.dll is less than 5.1.2600.135" test_ref="oval:org.mitre.oval:tst:1400"/>
                </criteria>
                <criteria operator="AND" comment="service pack 1 is installed and rpcss.dll is less than 5.1.2600.1361">
                  <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
                  <criterion comment="the version of rpcss.dll is less than 5.1.2600.1361" test_ref="oval:org.mitre.oval:tst:1399"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit version of Windows and rpcss.dll is less than 5.1.2600.1361">
              <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of rpcss.dll is less than 5.1.2600.1361" test_ref="oval:org.mitre.oval:tst:1399"/>
            </criteria>
          </criteria>
          <criterion negate="true" comment="the patch kb828741 is installed" test_ref="oval:org.mitre.oval:tst:1499"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="DCOM is enabled" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:957" version="0" class="vulnerability">
      <metadata>
        <title>Server 2003 RPCSS Service DCOM Activation Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0116"/>
        <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-09-27T11:12:00.000-04:00" comment="modified wft-199 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment="a vulnerable version of rpcss.dll exists on Server 2003">
            <criteria operator="AND" comment="32-bit machine a vulnerable version of rpcss.dll exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of rpcss.dll exists on non 64-bit Server 2003">
                <criterion comment="machine has followed the GDR update path and rpcss.dll is less than 5.2.3790.132" negate="false" test_ref="oval:org.mitre.oval:tst:1403"/>
                <criterion comment="machine has followed the QFE update path and rpcss.dll is less than 5.2.3790.142" negate="false" test_ref="oval:org.mitre.oval:tst:1402"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit machine and rpcss.dll is less than 5.2.3790.146">
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of rpcss.dll is less than 5.2.3790.142" negate="false" test_ref="oval:org.mitre.oval:tst:1401"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:956" version="4" class="vulnerability">
      <metadata>
        <title>IE .chm Directory Traversal Windows NT Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1041"/>
        <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:57.251-05:00">INTERIM</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected obj:964. Changed registry key name from a pattern match of .* to nil." date="2007-02-12T13:46:00.470-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:28.877-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:01:01.111-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:54.840-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criteria operator="OR" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed">
            <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
            <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2801"/>
            <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3123"/>
          </criteria>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion negate="true" comment="the patch kb840315 is installed" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion negate="true" comment="HTML Help is registered" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:955" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS Service DCOM Activation Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0116"/>
        <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.6906" negate="false" test_ref="oval:org.mitre.oval:tst:1407"/>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:954" version="2" class="vulnerability">
      <metadata>
        <title>Konqueror URI Handler "-" Filter Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0411"/>
        <description>The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.899-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.684-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1.3-6.4" negate="false" test_ref="oval:org.mitre.oval:tst:1426"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="telnet, rlogin, ssh or kmail is executable">
            <criteria operator="OR" comment="/usr/bin/telnet is executable">
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1425"/>
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1424"/>
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1423"/>
            </criteria>
            <criteria operator="OR" comment="/usr/kerberos/bin/telnet is executable">
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1422"/>
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1421"/>
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1420"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rlogin is executable">
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1419"/>
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1418"/>
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1417"/>
            </criteria>
            <criteria operator="OR" comment="/usr/kerberos/bin/rlogin is executable">
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1416"/>
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1415"/>
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1414"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ssh is executable">
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1413"/>
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1412"/>
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1411"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/kmail is executable">
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1410"/>
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1409"/>
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1408"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:952" version="3" class="vulnerability">
      <metadata>
        <title>NT4.0 SNMP Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>SNMP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0815"/>
        <description>Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-14T12:00:00.000-04:00" comment="Switched the service pack test from wrt-373 to wrt-539.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:01:00.709-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:54.471-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criterion comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" test_ref="oval:org.mitre.oval:tst:1427"/>
          <criterion negate="true" comment="Win2K/XP/2003 service pack 5 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="the SNMP service is enabled" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:951" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 SSL PCT Handshake Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Private Communications Transport (PCT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0719"/>
        <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:47.903-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:55.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2195.6899" negate="false" test_ref="oval:org.mitre.oval:tst:1501"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
          <criterion comment="PCT support is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1503"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:950" version="1">
      <metadata>
        <title>Microsoft Excel Malformed OBJECT record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-1306" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1306" source="CVE"/>
        <description>Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:40.980-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:50.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:95" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS ASP Server-Side Include Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0149"/>
        <description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.430-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:11.689-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:55.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:948" version="2" class="vulnerability">
      <metadata>
        <title>IE File Download Dialog Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0309"/>
        <description>Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:947" version="2" class="vulnerability">
      <metadata>
        <title>KAME IKE Daemon Improper Hash Value Handling</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0164" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0164"/>
        <description>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:05.590-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.481-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:946" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 H.323 Protocol Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>H.323</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0117"/>
        <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of h323.tsp is less than 5.2.3790.132" negate="false" test_ref="oval:org.mitre.oval:tst:1428"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:945" version="2" class="vulnerability">
      <metadata>
        <title>Racoon IKE Daemon Unauthorized X.509 Certificate Connection Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0155" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0155"/>
        <description>The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.509-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.312-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:944" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT IIS Cross-site Scripting Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1181"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:1448 to use obj:496 was introduced to properly look for w3svc.dll in System32/inetsrv." date="2007-07-18T12:59:00.571-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:02:21.706-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" negate="false" test_ref="oval:org.mitre.oval:tst:1448"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:943" version="2" class="vulnerability">
      <metadata>
        <title>Solaris Xsun and Xprt Unspecified Local Privilege Escalation</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3099"/>
        <description>Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.666-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.243-04:00">ACCEPTED</status_change>
            <modified comment="Corrected CVE reference and title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:00:00.106-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:01:36.132-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criterion comment="Solaris 7 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 108652-93 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3400"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 108653-82 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3355"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112785-50 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4130"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 112786-39 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3404"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 119059-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3997"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 119060-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3529"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criteria operator="AND" comment="File Xsun is SUID|SGID AND Executable" negate="false">
            <criteria operator="OR" comment="File Xsun SUID|SGID" negate="false">
              <criterion comment="File Xsun SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3963"/>
              <criterion comment="File Xprt SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3558"/>
            </criteria>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3178"/>
          </criteria>
          <criteria operator="AND" comment="File Xprt is SUID|SGID AND Executable" negate="false">
            <criteria operator="OR" comment="File Xprt SUID|SGID" negate="false">
              <criterion comment="File Xsun SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3963"/>
              <criterion comment="File Xprt SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3558"/>
            </criteria>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:942" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Cross-site Scripting Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1181"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:941" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Squid ACL Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0189"/>
        <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.635-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:10.144-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="squid version is less than 2.5.STABLE3-5.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1431"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:940" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel ISO9660 File System Component BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109"/>
        <description>Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:31.517-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="kernel versions">
            <criterion comment="kernel version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1436"/>
            <criterion comment="kernel-smp version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1435"/>
            <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1434"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/bin/mount is world-executable AND Set-UID">
            <criterion comment="/bin/mount is world-executable AND Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:1433"/>
            <criterion comment="/bin/mount is world-executable AND Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:1432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:94" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 mibiisa Remote Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mibiisa</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0797"/>
        <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File mibiisa exists" negate="false" test_ref="oval:org.mitre.oval:tst:2995"/>
          <criterion comment="Patch 108869-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3125"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mibiisa running" negate="false" test_ref="oval:org.mitre.oval:tst:2993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:939" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel ip_setsockopt Integer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0424" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0424"/>
        <description>Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.136-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="kernel versions">
          <criterion comment="kernel version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1436"/>
          <criterion comment="kernel-smp version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1435"/>
          <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1434"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:938" version="1" class="vulnerability">
      <metadata>
        <title>IIS5.0 Windows Media Services Large POST Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0349"/>
        <description>Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" negate="false" test_ref="oval:org.mitre.oval:tst:1437"/>
        <criterion comment="Patch KB822343 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:937" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mozilla Zombie Document Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0191"/>
        <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.073-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:936" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Media Services ISAPI Logging Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0227"/>
        <description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" negate="false" test_ref="oval:org.mitre.oval:tst:1440"/>
        <criterion comment="Patch KB817772 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1439"/>
        <criterion comment="Patch KB822343 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:935" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.649-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1442"/>
        <criterion comment="Patch PHNE_32606 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:933" version="3" class="vulnerability">
      <metadata>
        <title>IIS WebDAV Request Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0226"/>
        <description>Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:43:00.000-04:00" comment="modified wft-332 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:1444 to use obj:496 was introduced to properly look for w3svc.dll in System32/inetsrv." date="2007-07-18T12:59:00.963-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:02:05.118-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" negate="false" test_ref="oval:org.mitre.oval:tst:1444"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1443"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:932" version="1" class="vulnerability">
      <metadata>
        <title>IIS showcode.asp Sample File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0736"/>
        <description>The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\code.asp is less than 4.0.1381.279" negate="false" test_ref="oval:org.mitre.oval:tst:1446"/>
        <criterion comment="Patch Q232449 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1445"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:931" version="2" class="vulnerability">
      <metadata>
        <title>IIS5.0 Script Source Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1180"/>
        <description>A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:930" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Out of Process Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0869"/>
        <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:929" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT IIS Out of Process Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0869"/>
        <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:1448 to use obj:496 was introduced to properly look for w3svc.dll in System32/inetsrv." date="2007-07-18T12:59:00.571-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:02:21.945-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" negate="false" test_ref="oval:org.mitre.oval:tst:1448"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:928" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL Kerberos Handshake Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0112"/>
        <description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.729-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.352-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:927" version="1" class="vulnerability">
      <metadata>
        <title>IIS5.0 Specialized Header Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0778"/>
        <description>IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:926" version="2" class="vulnerability">
      <metadata>
        <title>IE URLMON Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0113"/>
        <description>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" negate="false" test_ref="oval:org.mitre.oval:tst:1449"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:925" version="3" class="vulnerability">
      <metadata>
        <title>MS IE HTML Directive Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0022"/>
        <description>Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" negate="false" test_ref="oval:org.mitre.oval:tst:1451"/>
          <criterion comment="Patch Q316059.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1458"/>
          <criterion comment="Patch Q319282 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1457"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="Run ActiveX Controls and Plugins Not Disabled">
            <criterion comment="Use Machine Settings" negate="false" test_ref="oval:org.mitre.oval:tst:1456"/>
            <criterion comment="Run ActiveX Controls and Plugins Allowed In At Least One Zone" negate="false" test_ref="oval:org.mitre.oval:tst:1450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:924" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 ASN.1 Library Double-free Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0123"/>
        <description>Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of msasn1.dll is less than 5.2.3790.139" test_ref="oval:org.mitre.oval:tst:1452"/>
        <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:923" version="3" class="vulnerability">
      <metadata>
        <title>Zone Spoofing through Malformed Web Page Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0190"/>
        <description>Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" negate="false" test_ref="oval:org.mitre.oval:tst:1453"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:922" version="2" class="vulnerability">
      <metadata>
        <title>IE Slash Characters in Type Property Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0344"/>
        <description>Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:921" version="3" class="vulnerability">
      <metadata>
        <title>IE File Execution User-prompt Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0727"/>
        <description>Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2712.0300" negate="false" test_ref="oval:org.mitre.oval:tst:1460"/>
          <criterion comment="Patch Q313675 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1459"/>
          <criterion comment="Patch Q316059.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1458"/>
          <criterion comment="Patch Q319282 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1457"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File Downloads Not Disabled">
            <criterion comment="Use Machine Settings" negate="false" test_ref="oval:org.mitre.oval:tst:1456"/>
            <criterion comment="File Downloads Allowed In At Least One Zone" negate="false" test_ref="oval:org.mitre.oval:tst:1455"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:920" version="1" class="vulnerability">
      <metadata>
        <title>IE Cached Content Command Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0002"/>
        <description>Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1466"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1465"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1464"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" negate="false" test_ref="oval:org.mitre.oval:tst:1463"/>
        <criterion comment="Patch Q286045 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1462"/>
        <criterion comment="Patch Q295106 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:92" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS HTTP Error Page Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0148"/>
        <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:919" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 LSASS Buffer Overflow (Sasser Worm Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0533" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0533"/>
        <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of lsasrv.dll is less than 5.2.3790.134" negate="false" test_ref="oval:org.mitre.oval:tst:1467"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:918" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Office Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-1316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1316" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:40.581-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:50.027-04:00">ACCEPTED</status_change>
            <modified date="2007-12-29T04:31:34" comment="Added application criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-01-01T09:14:18.051-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:19:33.229-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="A vulnerable application is installed">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <extend_definition comment="Microsoft Project 2000 SR1 is installed" definition_ref="oval:org.mitre.oval:def:518"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
        </criteria>
        <criteria operator="OR">
          <criteria operator="AND" comment="The 2000 version of the Mso9.dll library.">
            <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
            <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
          </criteria>
          <criteria operator="AND" comment="The 2002 version of the Mso.dll library.">
            <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
            <criterion comment="the version of Mso.dll is less than 10.0.6804.0." test_ref="oval:org.mitre.oval:tst:141"/>
          </criteria>
          <criteria operator="AND" comment="The 2003 version of the Mso.dll library.">
            <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
            <criterion comment="the version of Mso.dll is less than 11.0.8028.0." test_ref="oval:org.mitre.oval:tst:169"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:917" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mozilla Bypass Cookie Access Restrictions Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594"/>
        <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.843-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9165" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the KSSL Kernel Module May Lead to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3470" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3470"/>
        <description>Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured with the KSSL proxy, allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors related to "memory buffers" of Secure Socket Layer (SSL) records.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-03T10:36:57.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:51:06.630-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.053-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102918" negate="false">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4665" negate="true"/>
            <criterion comment="Patch 121474-01 or later installed" test_ref="oval:org.mitre.oval:tst:4207" negate="false"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102918" negate="false">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4966" negate="true"/>
            <criterion comment="Patch 121475-01 or later installed" test_ref="oval:org.mitre.oval:tst:4240" negate="false"/>
          </criteria>
        </criteria>
        <criterion comment="kssl running" negate="false" test_ref="oval:org.mitre.oval:tst:4861"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:915" version="2" class="vulnerability">
      <metadata>
        <title>IIS4.0 Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0874"/>
        <description>Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:1470 to use obj:496 which was introduced to properly look for w3svc.dll in System32/inetsrv." date="2007-07-18T13:08:00.040-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:09:22.266-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.479-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" negate="false" test_ref="oval:org.mitre.oval:tst:1470"/>
        <criterion comment="Win2K/XP/2003 service pack 6 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1469"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:914" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 S/MIME Protocol Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0564"/>
        <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.518-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:09.016-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:913" version="2" class="vulnerability">
      <metadata>
        <title>IIS ASP Source Code Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0278" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0278"/>
        <description>In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:1470 to use obj:496 which was introduced to properly look for w3svc.dll in System32/inetsrv." date="2007-07-18T13:08:00.040-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:09:22.473-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" negate="false" test_ref="oval:org.mitre.oval:tst:1470"/>
        <criterion comment="Win2K/XP/2003 service pack 6 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1469"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9127" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the IP Implementation for Solaris 8 and 9 May Allow a Denial of Service</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2045"/>
        <description>Unspecified vulnerability in the IP implementation in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (CPU consumption) via crafted IP packets, probably related to fragmented packets with duplicate or missing fragments.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-06T11:39:14.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-08T21:33:23.689-04:00">DRAFT</status_change>
            <status_change date="2007-08-23T14:55:20.078-04:00">INTERIM</status_change>
            <status_change date="2007-09-10T14:45:27.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102866" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 116965-26 or later installed" test_ref="oval:org.mitre.oval:tst:4585" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102866" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 114344-25 or later installed" test_ref="oval:org.mitre.oval:tst:4736" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102866" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 116966-25 or later installed" test_ref="oval:org.mitre.oval:tst:4659" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102866" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 119435-15 or later installed" test_ref="oval:org.mitre.oval:tst:4750" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:912" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS System File Listing Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0507"/>
        <description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-305 - changed the version of msw3prt.dll to test against from 5.5.2195.3649 to 5.0.2195.3649">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" negate="false" test_ref="oval:org.mitre.oval:tst:1471"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:911" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT Local Descriptor Table Kernel Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Local Descriptor Table (LDT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0910"/>
        <description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:01:00.349-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:53.973-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
        <criterion comment="the version of wintrust.dll is less than 5.131.1880.14" test_ref="oval:org.mitre.oval:tst:1472"/>
        <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:910" version="1" class="vulnerability">
      <metadata>
        <title>CSNW Remote Buffer Overflow via Network Messages (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1985"/>
        <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="nwwks.dll is less than 5.2.3790.2506" negate="false" test_ref="oval:org.mitre.oval:tst:1473"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:91" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE ToolTalk Database Null Write Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0677"/>
        <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:28.035-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.816-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 107893-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2969"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:909" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT IIS System File Listing Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0507"/>
        <description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:1474 to use obj:496 which was introduced to properly look for w3svc.dll in System32/inetsrv." date="2007-07-18T13:08:00.398-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:10:09.547-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" negate="false" test_ref="oval:org.mitre.oval:tst:1474"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:908" class="vulnerability" deprecated="true" version="1">
      <metadata>
        <title>Microsoft Client Service for NetWare Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4691"/>
        <description>Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:02.185-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:01.806-05:00">ACCEPTED</status_change>
            <modified date="2007-05-08T07:29:32.570-04:00" comment="Deprecated becased this definition is a duplicate of oval:org.mitre.oval:def:607">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-05-08T07:29:32.570-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wkssvc.dll is less than 5.0.2195.7108" test_ref="oval:org.mitre.oval:tst:73"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of wkssvc.dll is less than 5.1.2600.2976" test_ref="oval:org.mitre.oval:tst:113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:907" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 H.323 Protocol Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>H.323</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0117"/>
        <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of h323.tsp is less than 5.0.2195.6901" negate="false" test_ref="oval:org.mitre.oval:tst:1475"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:906" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Agent Security Prompt Spoofing Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Agent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1214"/>
        <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T08:32:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-17T09:54:00.000-04:00" comment="Updated obj:1000 to use new variable var:759 for path reference rather than var:200.  Now uses 'msagent' subdir of SystemRoot instead of System32.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-11-17T09:54:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:01.838-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment=" a vulnerable version of agentdpv exists">
            <criteria operator="AND" comment="a vulnerable version of agentdpv exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
              <criterion comment="the version of agentdpv.dll is less than 2.0.0.3423" test_ref="oval:org.mitre.oval:tst:2425"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of agentdpv exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1241" test_ref="oval:org.mitre.oval:tst:1476"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of agentdpv exists for Windows Gold 64-bit (x64)">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
              <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1241" test_ref="oval:org.mitre.oval:tst:1476"/>
            </criteria>
          </criteria>
          <criterion negate="true" comment="the patch kb890046 is installed" test_ref="oval:org.mitre.oval:tst:2424"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion negate="true" comment="use machine settings rather than individual user settings" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:905" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Ethereal Denial of Service via 0-Length Presentation Protocol Selector</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367"/>
        <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.816-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.565-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:904" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Help Center Command Insertion Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0907" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0907"/>
        <description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified date="2004-05-12T12:00:00.000-04:00" comment="Added a criterion to the configuration section to see if the HCP protocol is registered.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1001 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:40.350-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of helpctr.exe is less than 5.2.3790.125" negate="false" test_ref="oval:org.mitre.oval:tst:1478"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the HCP Protocol is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9039" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 10 Systems May Panic or Hang When Running Certain DTrace D Programs</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4126"/>
        <description>Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-02T11:47:26.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:50:57.753-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.800-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.047-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103021" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4221" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103021" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4704" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:903" version="3" class="vulnerability">
      <metadata>
        <title>Windows NT SSL PCT Handshake Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Private Communications Transport (PCT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0719"/>
        <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:47.653-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:55.032-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:59.903-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:53.521-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criterion comment="the version of schannel.dll is less than 4.87.1964.1880" test_ref="oval:org.mitre.oval:tst:1479"/>
          <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="SSL is enabled" test_ref="oval:org.mitre.oval:tst:1508"/>
          <criterion negate="true" comment="PCT support is disabled" test_ref="oval:org.mitre.oval:tst:1503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:902" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL Improper Unknown Message Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0081"/>
        <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.007-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:901" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 COM Structured Storage Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0047"/>
        <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-02-16T12:00:00.000-04:00" comment="Added compound statement to include three platforms">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-02-23T08:48:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of ole32.dll is less than 5.2.3790.250" negate="false" test_ref="oval:org.mitre.oval:tst:1486"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
        <criteria operator="OR" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed">
          <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:900" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP RPCSS DCOM Buffer Overflow (Blaster)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0813"/>
        <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="a vulnerable version of rpcrt4.dll exists on XP">
          <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of rpcrt4.dll exists">
            <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criteria operator="OR" comment="a vulnerable version of rpcrt4.dll exists depending on service pack level">
              <criteria operator="AND" comment="no service pack is installed and rpcrt4.dll is less than 5.1.2600.135">
                <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
                <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.135" test_ref="oval:org.mitre.oval:tst:1488"/>
              </criteria>
              <criteria operator="AND" comment="service pack 1 is installed and rpcrt4.dll is less than 5.1.2600.1361">
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
                <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.1361" test_ref="oval:org.mitre.oval:tst:1487"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and rpcrt4.dll is less than 5.1.2600.1361">
            <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.1361" test_ref="oval:org.mitre.oval:tst:1487"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="the patch kb828741 is installed" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:90" version="1" class="vulnerability">
      <metadata>
        <title>IIS Denial of Service via WebDAV</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0151"/>
        <description>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-10-20T10:07:00.000-04:00" comment="corrected configuration criterion">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" negate="false" test_ref="oval:org.mitre.oval:tst:2955"/>
          <criterion comment="Patch Q291845 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2954"/>
          <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
          <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3019"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="WebDav is disabled(for iis 5.0)" negate="true" test_ref="oval:org.mitre.oval:tst:2953"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8 RPC xdr_array Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>libnsl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391"/>
        <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:40.134-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:14:00.967-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:14:45.096-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.069-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criteria operator="OR" comment="rpc.cmsd or dmispd exist">
            <criterion comment="File rpc.cmsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3140"/>
            <criterion comment="File dmispd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3139"/>
          </criteria>
          <criteria operator="AND" comment="Patches 108827-30 and 108901-06" negate="true">
            <criterion comment="Patch 108827-30 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3138"/>
            <criterion comment="Patch 108901-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3137"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="rpc.cmsd enabled OR dmispd running">
            <criteria operator="AND" comment="rpc.cmsd enabled">
              <criterion comment="inetd.conf contains rpc.cmsd" negate="false" test_ref="oval:org.mitre.oval:tst:3136"/>
              <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
              <criteria operator="OR" comment="File rpc.cmsd executable">
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3134"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3133"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3132"/>
              </criteria>
            </criteria>
            <criterion comment="dmispd running" negate="false" test_ref="oval:org.mitre.oval:tst:3131"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:899" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.04 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.417-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.065-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:23:00.955-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:23:41.998-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.351-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.562-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33427 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:898" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP LSASS Buffer Overflow (Sasser Worm Vulnerability)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0533" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0533"/>
        <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:22:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criteria operator="OR" comment="a vulnerable version of lsasrv.dll exists on XP">
          <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of lsasrv.dll exists">
            <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criteria operator="OR" comment="a vulnerable version of lsasrv.dll exists depending on service pack level">
              <criteria operator="AND" comment="no service pack is installed and lsasrv.dll is less than 5.1.2600.134">
                <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
                <criterion comment="the version of lsasrv.dll is less than 5.1.2600.134" test_ref="oval:org.mitre.oval:tst:1490"/>
              </criteria>
              <criteria operator="AND" comment="service pack 1 is installed and lsasrv.dll is less than 5.1.2600.1361">
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
                <criterion comment="the version of lsasrv.dll is less than 5.1.2600.1361" test_ref="oval:org.mitre.oval:tst:1489"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and lsasrv.dll is less than 5.1.2600.1361">
            <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of lsasrv.dll is less than 5.1.2600.1361" test_ref="oval:org.mitre.oval:tst:1489"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:897" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT WMF/EMF Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Enhanced Metafile (EMF)</product>
          <product>Windows Metafile (WMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0906"/>
        <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:59.512-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:53.087-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
        <criteria operator="OR" comment="a vulnerable version of mf3216.dll exists on NT">
          <criteria operator="AND" comment="non Terminal Server and mf3216.dll is less than 4.0.1381.7263">
            <criterion negate="true" comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="the version of mf3216.dll is less than 4.0.1381.7263" test_ref="oval:org.mitre.oval:tst:1492"/>
          </criteria>
          <criteria operator="AND" comment="NT Terminal Server and mf3216.dll is less than 4.0.1381.33562">
            <criterion comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="the version of mf3216.dll is less than 4.0.1381.33562" test_ref="oval:org.mitre.oval:tst:1491"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:896" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 winlogon Remote Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows logon process (winlogon)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0806"/>
        <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:54:00.000-04:00" comment="modified wft-133 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-23T19:48:00.000-04:00" comment="fixed  tst:1493 by changing referrence to obj:862 (msgina.dll) instead of obj:958 (msjet40.dll).">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-09-23T20:21:00.000-04:00" comment="Replaced use of  tst:3085 to test for Windows 2000 with extended inventory definition def:85.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-09-23T21:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-10T20:40:01.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <extend_definition comment="Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msgina.dll is less than 5.0.2195.6895" negate="false" test_ref="oval:org.mitre.oval:tst:1493"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="machine is a member of a domain" negate="false" test_ref="oval:org.mitre.oval:tst:1494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:895" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT winlogon Remote Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows logon process (winlogon)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0806"/>
        <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:59.058-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:52.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criteria operator="OR" comment="a vulnerable version of msgina.dll exists on NT">
            <criteria operator="AND" comment="non Terminal Server and msgina.dll is less than 4.0.1381.7255">
              <criterion negate="true" comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
              <criterion comment="the version of msgina.dll is less than 4.0.1381.7255" test_ref="oval:org.mitre.oval:tst:1496"/>
            </criteria>
            <criteria operator="AND" comment="Terminal Server and msgina.dll is less than 4.0.1381.33559">
              <criterion comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
              <criterion comment="the version of msgina.dll is less than 4.0.1381.33559" test_ref="oval:org.mitre.oval:tst:1495"/>
            </criteria>
          </criteria>
          <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="machine is a member of a domain" test_ref="oval:org.mitre.oval:tst:1494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:894" version="0" class="vulnerability">
      <metadata>
        <title>Server 2003 RPCSS DCOM Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0813"/>
        <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="a vulnerable version of rpcrt4.dll exists on Server 2003">
          <criterion comment="machine has followed the GDR update path and rpcrt4.dll is less than 5.2.3790.137" negate="false" test_ref="oval:org.mitre.oval:tst:1498"/>
          <criterion comment="machine has followed the QFE update path and rpcrt4.dll is less than 5.2.3790.141" negate="false" test_ref="oval:org.mitre.oval:tst:1497"/>
        </criteria>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:893" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0813"/>
        <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6904" negate="false" test_ref="oval:org.mitre.oval:tst:1500"/>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:892" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 SSL Library Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Secure Sockets Layer (SSL)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0120"/>
        <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:48.669-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:54.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2195.6899" negate="false" test_ref="oval:org.mitre.oval:tst:1501"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:891" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Ethereal Denial of Service via Malformed RADIUS Packet</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365"/>
        <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:20.992-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:07.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:890" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Local Descriptor Table Kernel Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Descriptor Table (LDT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0910"/>
        <description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of wintrust.dll is less than 5.131.2195.6824" negate="false" test_ref="oval:org.mitre.oval:tst:1502"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:89" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 MUP UNC Request Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Multiple UNC Provider (MUP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0151"/>
        <description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" negate="false" test_ref="oval:org.mitre.oval:tst:2957"/>
        <criterion comment="Patch Q311967 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2956"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:889" version="3" class="vulnerability">
      <metadata>
        <title>Windows XP SSL PCT Handshake Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Private Communications Transport (PCT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0719"/>
        <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:21:00.000-04:00" comment="added cmp-66">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:48.106-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:54.311-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="a vulnerable version of schannel.dll exists">
            <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of schannel.dll exists">
              <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of schannel.dll exists depending on service pack level">
                <criteria operator="AND" comment="no service pack is installed and schannel.dll is less than 5.1.2600.136">
                  <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
                  <criterion comment="the version of schannel.dll is less than 5.1.2600.136" test_ref="oval:org.mitre.oval:tst:1507"/>
                </criteria>
                <criteria operator="AND" comment="service pack 1 is installed and schannel.dll is less than 5.1.2600.1347">
                  <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
                  <criterion comment="the version of schannel.dll is less than 5.1.2600.1347" test_ref="oval:org.mitre.oval:tst:1506"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit version of Windows and schannel.dll is less than 5.1.2600.1347">
              <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of schannel.dll is less than 5.1.2600.1347" test_ref="oval:org.mitre.oval:tst:1506"/>
            </criteria>
          </criteria>
          <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="SSL is enabled" test_ref="oval:org.mitre.oval:tst:1508"/>
          <criterion negate="true" comment="PCT support is disabled" test_ref="oval:org.mitre.oval:tst:1503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:888" version="3" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:44.943-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:01.509-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:887" version="2" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in Red Hat Enterprise 3 Ethereal</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176"/>
        <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.108-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:07.514-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:886" version="3" class="vulnerability">
      <metadata>
        <title>Windows XP SSL Library Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Secure Sockets Layer (SSL)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0120"/>
        <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T10:29:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:48.863-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:53.848-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="a vulnerable version of schannel.dll exists">
            <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of schannel.dll exists">
              <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of schannel.dll exists depending on service pack level">
                <criteria operator="AND" comment="no service pack is installed and schannel.dll is less than 5.1.2600.136">
                  <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
                  <criterion comment="the version of schannel.dll is less than 5.1.2600.136" test_ref="oval:org.mitre.oval:tst:1507"/>
                </criteria>
                <criteria operator="AND" comment="service pack 1 is installed and schannel.dll is less than 5.1.2600.1347">
                  <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
                  <criterion comment="the version of schannel.dll is less than 5.1.2600.1347" test_ref="oval:org.mitre.oval:tst:1506"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit version of Windows and schannel.dll is less than 5.1.2600.1347">
              <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of schannel.dll is less than 5.1.2600.1347" test_ref="oval:org.mitre.oval:tst:1506"/>
            </criteria>
          </criteria>
          <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="SSL is enabled" test_ref="oval:org.mitre.oval:tst:1508"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:885" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 SSL Library Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Secure Sockets Layer (SSL)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0120"/>
        <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:48.429-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:53.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.132" negate="false" test_ref="oval:org.mitre.oval:tst:1509"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:883" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 LSASS Buffer Overflow (Sasser Worm Vulnerability)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0533" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0533"/>
        <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of lsasrv.dll is less than 5.0.2195.6902" negate="false" test_ref="oval:org.mitre.oval:tst:1511"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:882" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v5.5,SP2 MHTML URL Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0380"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 5.5 SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1514"/>
        <criterion comment="the version of inetcomm.dll is less than 5.50.4939.300" negate="false" test_ref="oval:org.mitre.oval:tst:1513"/>
        <criterion comment="the patch kb837009 is installed (installed components key)" negate="true" test_ref="oval:org.mitre.oval:tst:1512"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:881" version="1" class="vulnerability">
      <metadata>
        <title>Bourne Shell Local-DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1780"/>
        <description>The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-14T06:41:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109324-09 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1520"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118535-03 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1519"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 121004-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1518"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109325-09 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1517"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118536-03 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1516"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121005-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1515"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:880" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Ethereal Denial of Service via 0-Length Presentation Protocol Selector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Red Hat 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367"/>
        <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.508-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:07.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:88" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal SPNEGO Dissoector Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0430" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0430"/>
        <description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.658-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:879" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Ethereal Denial of Service via Malformed RADIUS Packet</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Red Hat 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365"/>
        <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.657-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.701-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:878" version="2" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in Red Hat Ethereal</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Red Hat 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176"/>
        <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.429-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:877" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Squid ACL Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Red Hat 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0189"/>
        <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.363-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="squid version is less than 2.5STABLE1-3.9" negate="false" test_ref="oval:org.mitre.oval:tst:1533"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:876" version="2" class="vulnerability">
      <metadata>
        <title>Apache 2 Denial of Service due to Memory Leak in mod_ssl</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>httpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0113"/>
        <description>Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:31.325-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.035-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_ssl version is less than 2.0.46-32.ent" negate="false" test_ref="oval:org.mitre.oval:tst:1534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:875" version="2" class="vulnerability">
      <metadata>
        <title>XMLSoft Libxml2 Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>libxml2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0110"/>
        <description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-22T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.480-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.843-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="libxml2 version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1609"/>
          <criterion comment="libxml2-devel version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1608"/>
          <criterion comment="libxml2-python version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:874" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mozilla Zombie Document Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0191"/>
        <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.329-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mozilla version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1538"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mozilla is executable">
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1537"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1536"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:873" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mozilla Bypass Cookie Access Restrictions Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594"/>
        <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.788-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mozilla version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1538"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mozilla is executable">
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1537"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1536"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:872" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat S/MIME Protocol Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0564"/>
        <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.006-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.158-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1539"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:871" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL Improper Unknown Message Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0081"/>
        <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:42.840-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.958-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:870" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL do_change_cipher_spec Function Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.147-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:87" version="1" class="vulnerability">
      <metadata>
        <title>SNMPv1 Request Handling DoS and Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0013"/>
        <description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criterion negate="true" comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of snmp.exe is less than 4.0.1381.7134" test_ref="oval:org.mitre.oval:tst:2960"/>
          <criterion negate="true" comment="Patch Q314147 Installed" test_ref="oval:org.mitre.oval:tst:2959"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="the SNMP service is enabled" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:869" version="2" class="vulnerability">
      <metadata>
        <title>Net-SNMP MIB Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Net-SNMP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0935" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0935"/>
        <description>Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.441-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.539-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="net-snmp version is less than 5.0.9-2.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1545"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1544"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:868" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel eflags Checking Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0001"/>
        <description>Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:1547"/>
        <criterion comment="kernel version is less than 2.4.21-9.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1546"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:867" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Linux Kernel do_mremap Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985"/>
        <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:44.503-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1550"/>
          <criterion comment="kernel-smp version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1549"/>
          <criterion comment="kernel-bigmem version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1548"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:866" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 CVS Server root Directory Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977"/>
        <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.684-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:04.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-14" negate="false" test_ref="oval:org.mitre.oval:tst:1551"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/ is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:1576"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8653" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the TCP Loopback/Fusion Code May Lead to a System Hang Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3469"/>
        <description>Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local users to cause a denial of service (resource exhaustion and service hang) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-03T10:36:57.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:51:06.782-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.600-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.390-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102963" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4665" negate="true"/>
          <criterion comment="Patch 118833-17 or later installed" test_ref="oval:org.mitre.oval:tst:4625" negate="false"/>
          <criterion comment="Patch 118833-36 or earlier installed" test_ref="oval:org.mitre.oval:tst:4778" negate="false"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102963" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4966" negate="true"/>
          <criterion comment="Patch 118855-15 or later installed" test_ref="oval:org.mitre.oval:tst:4714" negate="false"/>
          <criterion comment="Patch 118855-36 or earlier installed" test_ref="oval:org.mitre.oval:tst:4725" negate="false"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:865" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 kdepim VCF File Information Reader BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>KDE Personal Information Management (kdepim)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0988"/>
        <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.566-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdepim version is less than 3.1.3-3.3" negate="false" test_ref="oval:org.mitre.oval:tst:1552"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/share/services/kfile_vcf.desktop is readable">
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1563"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1562"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:864" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Multiple stack-based BO Vulnerabilities in Apache</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.327-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.722-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.46-26.ent" negate="false" test_ref="oval:org.mitre.oval:tst:1553"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:863" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Multiple stack-based BO Vulnerabilities in Apache</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>httpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.702-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.9" negate="false" test_ref="oval:org.mitre.oval:tst:1554"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:862" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 sysstat port and trigger Scripts symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Sysstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0107"/>
        <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:21.223-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="sysstat version is less than 4.0.7-4.EL3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:861" version="2" class="vulnerability">
      <metadata>
        <title>rpc.mountd Denial of Service via NFS Mount</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>nfs-utils packages</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0154"/>
        <description>rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:26.329-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="nfs-utils version is less than 1.0.6-7.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1557"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.mountd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:860" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel do_mremap Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985"/>
        <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:42.419-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.810-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1560"/>
          <criterion comment="kernel-smp version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1559"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:86" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 LBXProxy Display Name Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>lbxproxy</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0090"/>
        <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File lbxproxy exists" negate="false" test_ref="oval:org.mitre.oval:tst:2964"/>
          <criterion comment="Patch 108652-51 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2963"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File lbxproxy SGID and executable">
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2962"/>
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2961"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:859" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel Real Time Clock Data Leakage</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0984"/>
        <description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.989-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1560"/>
          <criterion comment="kernel-smp version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1559"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:858" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat kdepim VCF File Information Reader BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDE Personal Information Management (kdepim)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0988"/>
        <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.520-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdepim version is less than 3.1-6" negate="false" test_ref="oval:org.mitre.oval:tst:1564"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/share/services/kfile_vcf.desktop is readable">
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1563"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1562"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:857" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal Malformed Q.931 Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Tethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1013"/>
        <description>The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.490-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1575"/>
            <criterion comment="ethereal-gnome version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1574"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1573"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1572"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1571"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1570"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1569"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1568"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/tethereal is executable">
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1567"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1566"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1565"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:856" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal Malformed SMB Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1012"/>
        <description>The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.899-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1575"/>
            <criterion comment="ethereal-gnome version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1574"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1573"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1572"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1571"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1570"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1569"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1568"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/tethereal is executable">
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1567"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1566"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1565"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:855" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat CVS Server root Directory Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>CVS server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977"/>
        <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.699-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-13" negate="false" test_ref="oval:org.mitre.oval:tst:1577"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/ is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:1576"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:854" version="3" class="vulnerability">
      <metadata>
        <title>RHE3 tcpdump DoS via ISAKMP Packets II</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057"/>
        <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:44.116-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:853" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 tcpdump Denial of Service via print_attr_string Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055"/>
        <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.687-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:852" version="2" class="vulnerability">
      <metadata>
        <title>RHE3 tcpdump DoS via ISAKMP Packets</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989"/>
        <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.952-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:851" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via ISAKMP Packets II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057"/>
        <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.838-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:850" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via print_attr_string Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055"/>
        <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:36.651-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:849" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat sysstat port and trigger Scripts symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>sysstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0107"/>
        <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.135-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="sysstat version is less than 4.0.7-4.rhl9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1579"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:848" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (64-bit WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="cdosys.dll is less than 6.5.6756.0" negate="false" test_ref="oval:org.mitre.oval:tst:2537"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:847" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via ISAKMP Packets</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989"/>
        <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.672-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.169-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:846" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat gdk-pixbuf Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0111"/>
        <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.497-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.959-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable configuration">
          <criterion comment="gdk-pixbuf version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1586"/>
          <criterion comment="gdk-pixbuf-devel version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1585"/>
          <criterion comment="gdk-pixbuf-gnome version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1584"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:845" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 gdk-pixbuf Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0111"/>
        <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:44.319-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable configuration">
          <criterion comment="gdk-pixbuf version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1589"/>
          <criterion comment="gdk-pixbuf-devel version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1588"/>
          <criterion comment="gdk-pixbuf-gnome version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:844" version="1" class="vulnerability">
      <metadata>
        <title>MSN Messenger Remote File Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0122"/>
        <description>Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-03-30T12:00:00.000-04:00" comment="Fixed the path for both versions of the file to look at the correct registry key to determine the location of the 'Program Files' folder..">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed">
          <criterion comment="the version of msgsc.dll is greater than 6.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:1591"/>
          <criterion comment="the version of msgsc.dll is less than 6.1.0.211" negate="false" test_ref="oval:org.mitre.oval:tst:1590"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:843" version="3" class="vulnerability">
      <metadata>
        <title>MS Outlook Argument Injection Local Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0121"/>
        <description>Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wft-130 - Added path to the end of the registry key specified in the first component of the file path">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:57:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1070: filename was utlook.exe instead of outlook.exe." date="2007-01-22T14:51:00.798-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T14:52:28.908-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:01.279-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1595"/>
        <criterion comment="the version of outlook.exe is less than 10.00.5709.0000" negate="false" test_ref="oval:org.mitre.oval:tst:1594"/>
        <criterion comment="the patch kb828040 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1593"/>
        <criterion comment="Microsoft Office XP Service Pack 3 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1592"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:842" version="0" class="vulnerability">
      <metadata>
        <title>MS Windows Media Service Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0905"/>
        <description>Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <modified comment="Fixed obj:1078: Removed HKEY_LOCAL_MACHINE\ from the key, as it's specified as the hive.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:34:00.741-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.292-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.906-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server">
            <criterion comment="Windows Media Services 4.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1602"/>
            <criteria operator="AND" comment="Windows 2000 Server is installed">
              <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
              <criteria operator="OR" comment="Windows NT server product option">
                <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
                <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="the version of nscm.exe is less than 4.1.0.3934" negate="false" test_ref="oval:org.mitre.oval:tst:1601"/>
          <criterion comment="the version of nspmon.exe is less than 4.1.0.3934" negate="false" test_ref="oval:org.mitre.oval:tst:1600"/>
          <criterion comment="the patch kb832359 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1599"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="configured to only offer streaming media over unicast" negate="true" test_ref="oval:org.mitre.oval:tst:1598"/>
          <criterion comment="the Windows Media Station service is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1597"/>
          <criterion comment="the Windows Media Monitor service is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1596"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:841" version="1">
      <metadata>
        <title>Unhandled Exception Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3648" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:39.810-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:49.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Kernel32.dll is less than 5.0.2195.7099" test_ref="oval:org.mitre.oval:tst:80"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Kernel32.dll is less than 5.1.2600.1869" test_ref="oval:org.mitre.oval:tst:31"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Kernel32.dll is less than 5.1.2600.2945" test_ref="oval:org.mitre.oval:tst:45"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.2741" test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.556" test_ref="oval:org.mitre.oval:tst:63"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.2741" test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:840" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:84" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.12 Vulnerability in OSI Dissector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0429" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0429"/>
        <description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.040-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:839" version="2" deprecated="true" class="vulnerability">
      <metadata>
        <title>mod_python Web Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mod_python</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973"/>
        <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.304-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.430-04:00">ACCEPTED</status_change>
            <modified date="2007-05-08T07:29:32.570-04:00" comment="Deprecated becased this definition is a duplicate of oval:org.mitre.oval:def:828">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-08T07:29:32.570-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_python version is less than 3.0.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:1612"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:838" version="3" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mutt BO in Index Menu</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0078"/>
        <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.067-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-3.4" negate="false" test_ref="oval:org.mitre.oval:tst:1603"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:837" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel do_mremap Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mremap</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077"/>
        <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.124-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.044-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:836" version="2" class="vulnerability">
      <metadata>
        <title>Vicam USB Driver Data Copy Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Vicam USB driver</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0075"/>
        <description>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:52.053-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.802-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:835" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel ncp_lookup Function BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010"/>
        <description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.479-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:834" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel R128 DRI Limits Checking Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003"/>
        <description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:58.073-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8334" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in lbxproxy(1) may Allow Unauthorized Read Access to Files</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4070"/>
        <description>Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 20070725 allows local users to read arbitrary files with root group ownership via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-01T13:14:10.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-01T22:21:39.310-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.437-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 119067-08 or later installed" test_ref="oval:org.mitre.oval:tst:5089" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112785-62 or later installed" test_ref="oval:org.mitre.oval:tst:4378" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119059-28 or later installed" test_ref="oval:org.mitre.oval:tst:4559" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 119068-08 or later installed" test_ref="oval:org.mitre.oval:tst:4495" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 112786-51 or later installed" test_ref="oval:org.mitre.oval:tst:4915" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119060-27 or later installed" test_ref="oval:org.mitre.oval:tst:5067" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:833" version="2" deprecated="true" class="vulnerability">
      <metadata>
        <title>XMLSoft Libxml2 Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XMLSoft Libxml2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0110"/>
        <description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.353-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.231-04:00">ACCEPTED</status_change>
            <modified date="2007-05-08T07:29:32.570-04:00" comment="Deprecated becased this definition is a duplicate of oval:org.mitre.oval:def:875">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-08T07:29:32.570-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="libxml2 version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1609"/>
          <criterion comment="libxml2-devel version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1608"/>
          <criterion comment="libxml2-python version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:832" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Improper Handling of Font Files</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106"/>
        <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:53.814-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:831" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Buffer Overflow in CopyISOLatin1Lowered Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084"/>
        <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.698-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:830" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Buffer Overflow in dirfile</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083"/>
        <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.757-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.643-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:83" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft SQL Server 3-Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>MicrosoftSQL Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0542"/>
        <description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-227 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:57:00.000-04:00" comment="modified wft-227 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File sqlservr.exe version3 less than 2000.80.428.0" negate="false" test_ref="oval:org.mitre.oval:tst:2965"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:8280" version="1">
      <metadata>
        <title>OpenOffice_org WMF buffer overflows</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux Professional 9.3</platform>
          <platform>SUSE Linux Desktop 1.0</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
          <product>OpenOffice_org1</product>
          <product>OpenOffice_org1-ar</product>
          <product>OpenOffice_org1-ca</product>
          <product>OpenOffice_org1-cs</product>
          <product>OpenOffice_org1-da</product>
          <product>OpenOffice_org1-de</product>
          <product>OpenOffice_org1-el</product>
          <product>OpenOffice_org1-en</product>
          <product>OpenOffice_org1-es</product>
          <product>OpenOffice_org1-et</product>
          <product>OpenOffice_org1-fi</product>
          <product>OpenOffice_org1-fr</product>
          <product>OpenOffice_org1-gnome</product>
          <product>OpenOffice_org1-hu</product>
          <product>OpenOffice_org1-it</product>
          <product>OpenOffice_org1-ja</product>
          <product>OpenOffice_org1-kde</product>
          <product>OpenOffice_org1-ko</product>
          <product>OpenOffice_org1-nl</product>
          <product>OpenOffice_org1-pl</product>
          <product>OpenOffice_org1-pt</product>
          <product>OpenOffice_org1-ru</product>
          <product>OpenOffice_org1-sk</product>
          <product>OpenOffice_org1-sl</product>
          <product>OpenOffice_org1-sv</product>
          <product>OpenOffice_org1-tr</product>
          <product>OpenOffice_org1-zh-CN</product>
          <product>OpenOffice_org1-zh-TW</product>
          <product>OpenOffice_org</product>
          <product>OpenOffice_org-af</product>
          <product>OpenOffice_org-be-BY</product>
          <product>OpenOffice_org-bg</product>
          <product>OpenOffice_org-ca</product>
          <product>OpenOffice_org-cs</product>
          <product>OpenOffice_org-cy</product>
          <product>OpenOffice_org-da</product>
          <product>OpenOffice_org-de</product>
          <product>OpenOffice_org-el</product>
          <product>OpenOffice_org-en</product>
          <product>OpenOffice_org-en-GB</product>
          <product>OpenOffice_org-es</product>
          <product>OpenOffice_org-et</product>
          <product>OpenOffice_org-fi</product>
          <product>OpenOffice_org-fr</product>
          <product>OpenOffice_org-galleries</product>
          <product>OpenOffice_org-gnome</product>
          <product>OpenOffice_org-gu-IN</product>
          <product>OpenOffice_org-hr</product>
          <product>OpenOffice_org-hu</product>
          <product>OpenOffice_org-hunspell</product>
          <product>OpenOffice_org-it</product>
          <product>OpenOffice_org-ja</product>
          <product>OpenOffice_org-kde</product>
          <product>OpenOffice_org-ko</product>
          <product>OpenOffice_org-mono</product>
          <product>OpenOffice_org-nb</product>
          <product>OpenOffice_org-nl</product>
          <product>OpenOffice_org-nn</product>
          <product>OpenOffice_org-officebean</product>
          <product>OpenOffice_org-pa-IN</product>
          <product>OpenOffice_org-pl</product>
          <product>OpenOffice_org-pt</product>
          <product>OpenOffice_org-pt-BR</product>
          <product>OpenOffice_org-ru</product>
          <product>OpenOffice_org-sk</product>
          <product>OpenOffice_org-sl</product>
          <product>OpenOffice_org-sv</product>
          <product>OpenOffice_org-tr</product>
          <product>OpenOffice_org-vi</product>
          <product>OpenOffice_org-xh</product>
          <product>OpenOffice_org-zh-CN</product>
          <product>OpenOffice_org-zh-TW</product>
          <product>OpenOffice_org-zu</product>
        </affected>
        <reference ref_id="CVE-2006-5870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5870" source="CVE"/>
        <description>Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-22T11:38:47">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:07.872-04:00">DRAFT</status_change>
            <modified comment="Assigned new id to ste used for tst:4278." date="2007-08-02T14:42:00.077-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-08-20T08:04:41.466-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe://novell:linux_desktop:9</cpe>
            <cpe>cpe://novell:suse_linux:10.1</cpe>
            <cpe>cpe://novell:suse_linux:10.0</cpe>
            <cpe>cpe://novell:suse_linux:9.3:pro</cpe>
            <cpe>cpe://novell:suse_linux:1.0:desktop</cpe>
            <cpe>cpe://novell:suse_linux_enterprise:10:desktop</cpe>
            <cpe>cpe:///novell:OpenOffice_org1</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-ar</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-ca</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-cs</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-da</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-de</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-el</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-en</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-es</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-et</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-fi</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-fr</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-gnome</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-hu</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-it</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-ja</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-kde</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-ko</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-nl</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-pl</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-pt</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-ru</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-sk</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-sl</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-sv</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-tr</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-zh-CN</cpe>
            <cpe>cpe:///novell:OpenOffice_org1-zh-TW</cpe>
            <cpe>cpe:///novell:OpenOffice_org</cpe>
            <cpe>cpe:///novell:OpenOffice_org-af</cpe>
            <cpe>cpe:///novell:OpenOffice_org-be-BY</cpe>
            <cpe>cpe:///novell:OpenOffice_org-bg</cpe>
            <cpe>cpe:///novell:OpenOffice_org-ca</cpe>
            <cpe>cpe:///novell:OpenOffice_org-cs</cpe>
            <cpe>cpe:///novell:OpenOffice_org-cy</cpe>
            <cpe>cpe:///novell:OpenOffice_org-da</cpe>
            <cpe>cpe:///novell:OpenOffice_org-de</cpe>
            <cpe>cpe:///novell:OpenOffice_org-el</cpe>
            <cpe>cpe:///novell:OpenOffice_org-en</cpe>
            <cpe>cpe:///novell:OpenOffice_org-en-GB</cpe>
            <cpe>cpe:///novell:OpenOffice_org-es</cpe>
            <cpe>cpe:///novell:OpenOffice_org-et</cpe>
            <cpe>cpe:///novell:OpenOffice_org-fi</cpe>
            <cpe>cpe:///novell:OpenOffice_org-fr</cpe>
            <cpe>cpe:///novell:OpenOffice_org-galleries</cpe>
            <cpe>cpe:///novell:OpenOffice_org-gnome</cpe>
            <cpe>cpe:///novell:OpenOffice_org-gu-IN</cpe>
            <cpe>cpe:///novell:OpenOffice_org-hr</cpe>
            <cpe>cpe:///novell:OpenOffice_org-hu</cpe>
            <cpe>cpe:///novell:OpenOffice_org-hunspell</cpe>
            <cpe>cpe:///novell:OpenOffice_org-it</cpe>
            <cpe>cpe:///novell:OpenOffice_org-ja</cpe>
            <cpe>cpe:///novell:OpenOffice_org-kde</cpe>
            <cpe>cpe:///novell:OpenOffice_org-ko</cpe>
            <cpe>cpe:///novell:OpenOffice_org-mono</cpe>
            <cpe>cpe:///novell:OpenOffice_org-nb</cpe>
            <cpe>cpe:///novell:OpenOffice_org-nl</cpe>
            <cpe>cpe:///novell:OpenOffice_org-nn</cpe>
            <cpe>cpe:///novell:OpenOffice_org-officebean</cpe>
            <cpe>cpe:///novell:OpenOffice_org-pa-IN</cpe>
            <cpe>cpe:///novell:OpenOffice_org-pl</cpe>
            <cpe>cpe:///novell:OpenOffice_org-pt</cpe>
            <cpe>cpe:///novell:OpenOffice_org-pt-BR</cpe>
            <cpe>cpe:///novell:OpenOffice_org-ru</cpe>
            <cpe>cpe:///novell:OpenOffice_org-sk</cpe>
            <cpe>cpe:///novell:OpenOffice_org-sl</cpe>
            <cpe>cpe:///novell:OpenOffice_org-sv</cpe>
            <cpe>cpe:///novell:OpenOffice_org-tr</cpe>
            <cpe>cpe:///novell:OpenOffice_org-vi</cpe>
            <cpe>cpe:///novell:OpenOffice_org-xh</cpe>
            <cpe>cpe:///novell:OpenOffice_org-zh-CN</cpe>
            <cpe>cpe:///novell:OpenOffice_org-zh-TW</cpe>
            <cpe>cpe:///novell:OpenOffice_org-zu</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria comment="Exploitable Vulnerability Exists" operator="OR">
        <criteria comment="Exploitable Novell Linux Desktop 9 or SUSE Linux Desktop 1.0 Vulnerability Exists" operator="AND">
          <criteria comment="Potential System Vulnerability Exists" operator="AND">
            <criteria comment="Potential Novell Linux Desktop 9 or SUSE Linux Desktop 1.0 Vulnerability Exists" operator="OR">
              <extend_definition comment="Novell Linux Desktop 9 is installed" negate="false" definition_ref="oval:org.mitre.oval:def:2090"/>
              <extend_definition comment="SUSE Linux Desktop 1.0 is installed" negate="false" definition_ref="oval:org.mitre.oval:def:1366"/>
            </criteria>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          </criteria>
          <criteria comment="Potential Package Vulnerability Exists" operator="OR">
            <criterion comment="Package OpenOffice_org is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4677"/>
            <criterion comment="Package OpenOffice_org-ar is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4205"/>
            <criterion comment="Package OpenOffice_org-ca is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4866"/>
            <criterion comment="Package OpenOffice_org-cs is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4348"/>
            <criterion comment="Package OpenOffice_org-da is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4791"/>
            <criterion comment="Package OpenOffice_org-de is installed" negate="false" test_ref="oval:org.mitre.oval:tst:5008"/>
            <criterion comment="Package OpenOffice_org-el is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4238"/>
            <criterion comment="Package OpenOffice_org-en is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4287"/>
            <criterion comment="Package OpenOffice_org-es is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4751"/>
            <criterion comment="Package OpenOffice_org-et is installed" negate="false" test_ref="oval:org.mitre.oval:tst:5033"/>
            <criterion comment="Package OpenOffice_org-fi is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4254"/>
            <criterion comment="Package OpenOffice_org-fr is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4518"/>
            <criterion comment="Package OpenOffice_org-gnome is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4675"/>
            <criterion comment="Package OpenOffice_org-hu is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4235"/>
            <criterion comment="Package OpenOffice_org-it is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4849"/>
            <criterion comment="Package OpenOffice_org-ja is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4671"/>
            <criterion comment="Package OpenOffice_org-kde is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4544"/>
            <criterion comment="Package OpenOffice_org-ko is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4941"/>
            <criterion comment="Package OpenOffice_org-nl is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4956"/>
            <criterion comment="Package OpenOffice_org-pl is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4556"/>
            <criterion comment="Package OpenOffice_org-pt is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4724"/>
            <criterion comment="Package OpenOffice_org-pt-BR is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4754"/>
            <criterion comment="Package OpenOffice_org-ru is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4980"/>
            <criterion comment="Package OpenOffice_org-sk is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4739"/>
            <criterion comment="Package OpenOffice_org-sl is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4596"/>
            <criterion comment="Package OpenOffice_org-sv is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4550"/>
            <criterion comment="Package OpenOffice_org-tr is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4210"/>
            <criterion comment="Package OpenOffice_org-zh-CN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4875"/>
            <criterion comment="Package OpenOffice_org-zh-TW is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4555"/>
          </criteria>
        </criteria>
        <criteria comment="Exploitable SUSE Linux 10.1 Vulnerability Exists" operator="AND">
          <criteria comment="Potential System Vulnerability Exists" operator="AND">
            <extend_definition comment="SUSE Linux 10.1 is installed" negate="false" definition_ref="oval:org.mitre.oval:def:2157"/>
            <criteria comment="Potential Architecture Vulnerability Exists" operator="OR">
              <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
              <criterion comment="ppc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:4278"/>
            </criteria>
          </criteria>
          <criteria comment="Potential Package Vulnerability Exists" operator="OR">
            <criteria comment="Potential Package OpenOffice_org Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8865"/>
              <criterion comment="Package OpenOffice_org version-release is less than 2.0.2-27.15" negate="false" test_ref="oval:org.mitre.oval:tst:4673"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-gnome Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-gnome is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8914"/>
              <criterion comment="Package OpenOffice_org-gnome version-release is less than 2.0.2-27.15" negate="false" test_ref="oval:org.mitre.oval:tst:4905"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-kde Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-kde is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9199"/>
              <criterion comment="Package OpenOffice_org-kde version-release is less than 2.0.2-27.15" negate="false" test_ref="oval:org.mitre.oval:tst:4272"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-mono Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-mono is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8222"/>
              <criterion comment="Package OpenOffice_org-mono version-release is less than 2.0.2-27.15" negate="false" test_ref="oval:org.mitre.oval:tst:4421"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-officebean Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-officebean is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8541"/>
              <criterion comment="Package OpenOffice_org-officebean version-release is less than 2.0.2-27.15" negate="false" test_ref="oval:org.mitre.oval:tst:5087"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Exploitable SUSE Linux 10.0 Vulnerability Exists" operator="AND">
          <criteria comment="Potential System Vulnerability Exists" operator="AND">
            <extend_definition comment="SUSE Linux 10.0 is installed" negate="false" definition_ref="oval:org.mitre.oval:def:2027"/>
            <criteria comment="Potential Architecture Vulnerability Exists" operator="OR">
              <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
              <criterion comment="ppc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:4278"/>
            </criteria>
          </criteria>
          <criteria comment="Potential Package Vulnerability Exists" operator="OR">
            <criteria comment="Potential Package OpenOffice_org Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8865"/>
              <criterion comment="Package OpenOffice_org version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4770"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-af Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-af is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8974"/>
              <criterion comment="Package OpenOffice_org-af version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5076"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-ar Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-ar is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8663"/>
              <criterion comment="Package OpenOffice_org-ar version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4524"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-be-BY Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-be-BY is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8432"/>
              <criterion comment="Package OpenOffice_org-be-BY version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4761"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-bg Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-bg is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8403"/>
              <criterion comment="Package OpenOffice_org-bg version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4224"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-ca Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-ca is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8887"/>
              <criterion comment="Package OpenOffice_org-ca version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4449"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-cs Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-cs is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8733"/>
              <criterion comment="Package OpenOffice_org-cs version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4479"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-cy Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-cy is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8329"/>
              <criterion comment="Package OpenOffice_org-cy version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4986"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-da Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-da is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8998"/>
              <criterion comment="Package OpenOffice_org-da version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4833"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-de Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-de is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8688"/>
              <criterion comment="Package OpenOffice_org-de version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4410"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-el Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-el is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8801"/>
              <criterion comment="Package OpenOffice_org-el version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4561"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-en-GB Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-en-GB is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8829"/>
              <criterion comment="Package OpenOffice_org-en-GB version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4226"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-es Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-es is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8583"/>
              <criterion comment="Package OpenOffice_org-es version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4656"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-et Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-et is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8678"/>
              <criterion comment="Package OpenOffice_org-et version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5031"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-fi Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-fi is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8451"/>
              <criterion comment="Package OpenOffice_org-fi version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4716"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-fr Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-fr is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8215"/>
              <criterion comment="Package OpenOffice_org-fr version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5020"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-galleries Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-galleries is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8997"/>
              <criterion comment="Package OpenOffice_org-galleries version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4981"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-gnome Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-gnome is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8914"/>
              <criterion comment="Package OpenOffice_org-gnome version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5098"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-gu-IN Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-gu-IN is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8341"/>
              <criterion comment="Package OpenOffice_org-gu-IN version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4763"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-hr Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-hr is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8715"/>
              <criterion comment="Package OpenOffice_org-hr version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4280"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-hu Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-hu is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8228"/>
              <criterion comment="Package OpenOffice_org-hu version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5191"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-hunspell Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-hunspell is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8892"/>
              <criterion comment="Package OpenOffice_org-hunspell version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5152"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-it Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-it is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9104"/>
              <criterion comment="Package OpenOffice_org-it version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4644"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-ja Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-ja is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8987"/>
              <criterion comment="Package OpenOffice_org-ja version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4620"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-kde Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-kde is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9199"/>
              <criterion comment="Package OpenOffice_org-kde version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4921"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-ko Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-ko is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8352"/>
              <criterion comment="Package OpenOffice_org-ko version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5038"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-mono Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-mono is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8222"/>
              <criterion comment="Package OpenOffice_org-mono version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5103"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-nb Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-nb is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8804"/>
              <criterion comment="Package OpenOffice_org-nb version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5128"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-nl Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-nl is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8611"/>
              <criterion comment="Package OpenOffice_org-nl version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4520"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-nn Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-nn is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8501"/>
              <criterion comment="Package OpenOffice_org-nn version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4274"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-officebean Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-officebean is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8541"/>
              <criterion comment="Package OpenOffice_org-officebean version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4420"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-pa-IN Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-pa-IN is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8882"/>
              <criterion comment="Package OpenOffice_org-pa-IN version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4209"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-pl Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-pl is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8799"/>
              <criterion comment="Package OpenOffice_org-pl version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4456"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-pt Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-pt is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8664"/>
              <criterion comment="Package OpenOffice_org-pt version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4940"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-pt-BR Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-pt-BR is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8886"/>
              <criterion comment="Package OpenOffice_org-pt-BR version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5180"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-ru Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-ru is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8389"/>
              <criterion comment="Package OpenOffice_org-ru version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5096"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-sk Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-sk is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8244"/>
              <criterion comment="Package OpenOffice_org-sk version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5058"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-sl Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-sl is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9181"/>
              <criterion comment="Package OpenOffice_org-sl version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4908"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-sv Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-sv is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8860"/>
              <criterion comment="Package OpenOffice_org-sv version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:5051"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-tr Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-tr is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8707"/>
              <criterion comment="Package OpenOffice_org-tr version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4258"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-vi Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-vi is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8288"/>
              <criterion comment="Package OpenOffice_org-vi version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4828"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-xh Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-xh is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8477"/>
              <criterion comment="Package OpenOffice_org-xh version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4893"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-zh-CN Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-zh-CN is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8995"/>
              <criterion comment="Package OpenOffice_org-zh-CN version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4331"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-zh-TW Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-zh-TW is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9146"/>
              <criterion comment="Package OpenOffice_org-zh-TW version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4204"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org-zu Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org-zu is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8269"/>
              <criterion comment="Package OpenOffice_org-zu version-release is less than 2.0.0-1.6" negate="false" test_ref="oval:org.mitre.oval:tst:4850"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Exploitable SUSE Linux Professional 9.3 Vulnerability Exists" operator="AND">
          <criteria comment="Potential System Vulnerability Exists" operator="AND">
            <extend_definition comment="SUSE Linux Professional 9.3 is installed" negate="false" definition_ref="oval:org.mitre.oval:def:2044"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          </criteria>
          <criteria comment="Potential Package Vulnerability Exists" operator="OR">
            <criteria comment="Potential Package OpenOffice_org1 Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1 is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8264"/>
              <criterion comment="Package OpenOffice_org1 version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4622"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-ar Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-ar is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8777"/>
              <criterion comment="Package OpenOffice_org1-ar version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4923"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-ca Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-ca is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8915"/>
              <criterion comment="Package OpenOffice_org1-ca version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:5069"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-cs Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-cs is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8357"/>
              <criterion comment="Package OpenOffice_org1-cs version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4463"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-da Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-da is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8308"/>
              <criterion comment="Package OpenOffice_org1-da version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:5139"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-de Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-de is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8533"/>
              <criterion comment="Package OpenOffice_org1-de version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4368"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-el Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-el is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8652"/>
              <criterion comment="Package OpenOffice_org1-el version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4650"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-en Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-en is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8958"/>
              <criterion comment="Package OpenOffice_org1-en version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4537"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-es Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-es is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8705"/>
              <criterion comment="Package OpenOffice_org1-es version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4937"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-et Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-et is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8681"/>
              <criterion comment="Package OpenOffice_org1-et version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4627"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-fi Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-fi is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8815"/>
              <criterion comment="Package OpenOffice_org1-fi version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4462"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-fr Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-fr is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8672"/>
              <criterion comment="Package OpenOffice_org1-fr version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4404"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-gnome Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-gnome is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8342"/>
              <criterion comment="Package OpenOffice_org1-gnome version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4713"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-hu Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-hu is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8380"/>
              <criterion comment="Package OpenOffice_org1-hu version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:5127"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-it Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-it is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8691"/>
              <criterion comment="Package OpenOffice_org1-it version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4541"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-ja Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-ja is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9174"/>
              <criterion comment="Package OpenOffice_org1-ja version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4727"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-kde Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-kde is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8774"/>
              <criterion comment="Package OpenOffice_org1-kde version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4594"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-ko Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-ko is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9070"/>
              <criterion comment="Package OpenOffice_org1-ko version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4816"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-nl Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-nl is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9192"/>
              <criterion comment="Package OpenOffice_org1-nl version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4590"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-pl Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-pl is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8502"/>
              <criterion comment="Package OpenOffice_org1-pl version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:5010"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-pt Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-pt is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8906"/>
              <criterion comment="Package OpenOffice_org1-pt version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:5028"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-ru Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-ru is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9169"/>
              <criterion comment="Package OpenOffice_org1-ru version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4728"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-sk Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-sk is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8903"/>
              <criterion comment="Package OpenOffice_org1-sk version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:5118"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-sl Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-sl is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8773"/>
              <criterion comment="Package OpenOffice_org1-sl version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4598"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-sv Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-sv is installed" negate="false" definition_ref="oval:org.mitre.oval:def:9168"/>
              <criterion comment="Package OpenOffice_org1-sv version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4806"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-tr Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-tr is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8310"/>
              <criterion comment="Package OpenOffice_org1-tr version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4775"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-zh-CN Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-zh-CN is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8604"/>
              <criterion comment="Package OpenOffice_org1-zh-CN version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:5086"/>
            </criteria>
            <criteria comment="Potential Package OpenOffice_org1-zh-TW Vulnerability Exists" operator="AND">
              <extend_definition comment="Package OpenOffice_org1-zh-TW is installed" negate="false" definition_ref="oval:org.mitre.oval:def:8999"/>
              <criterion comment="Package OpenOffice_org1-zh-TW version-release is less than 1.1.3-4.7" negate="false" test_ref="oval:org.mitre.oval:tst:4376"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Exploitable SUSE Linux Enterprise Desktop 10 Vulnerability Exists" operator="AND">
          <criteria comment="Potential System Vulnerability Exists" operator="AND">
            <extend_definition comment="SUSE Linux Enterprise Desktop 10 is installed" negate="false" definition_ref="oval:org.mitre.oval:def:2106"/>
            <criteria comment="Potential Architecture Vulnerability Exists" operator="OR">
              <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
              <criterion comment="x86_64 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:1547"/>
            </criteria>
          </criteria>
          <criteria comment="Potential Package Vulnerability Exists" operator="OR">
            <criterion comment="Package OpenOffice_org is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4677"/>
            <criterion comment="Package OpenOffice_org-gnome is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4675"/>
            <criterion comment="Package OpenOffice_org-kde is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4544"/>
            <criterion comment="Package OpenOffice_org-mono is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9199" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-kde is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:OpenOffice_org-kde"/>
        <description>Package OpenOffice_org-kde is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:11">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.674-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.395-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.790-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-kde is installed" test_ref="oval:org.mitre.oval:tst:4544"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9192" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-nl is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-nl"/>
        <description>Package OpenOffice_org1-nl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.778-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.343-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.725-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-nl is installed" test_ref="oval:org.mitre.oval:tst:4451"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9181" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-sl is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-sl"/>
        <description>Package OpenOffice_org-sl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:42">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.411-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.286-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-sl is installed" test_ref="oval:org.mitre.oval:tst:4596"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9174" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ja is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ja"/>
        <description>Package OpenOffice_org1-ja is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.648-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.230-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ja is installed" test_ref="oval:org.mitre.oval:tst:4794"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9169" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ru is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ru"/>
        <description>Package OpenOffice_org1-ru is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.904-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.177-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.477-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ru is installed" test_ref="oval:org.mitre.oval:tst:4542"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9168" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-sv is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-sv"/>
        <description>Package OpenOffice_org1-sv is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.040-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.125-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.418-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-sv is installed" test_ref="oval:org.mitre.oval:tst:4290"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9146" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-zh-TW is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-zh-TW"/>
        <description>Package OpenOffice_org-zh-TW is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:38">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.764-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.980-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-zh-TW is installed" test_ref="oval:org.mitre.oval:tst:4555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9104" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-it is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-it"/>
        <description>Package OpenOffice_org-it is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:04">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.574-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.918-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-it is installed" test_ref="oval:org.mitre.oval:tst:4849"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9070" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ko is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ko"/>
        <description>Package OpenOffice_org1-ko is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.732-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.863-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ko is installed" test_ref="oval:org.mitre.oval:tst:4418"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8999" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-zh-TW is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-zh-TW"/>
        <description>Package OpenOffice_org1-zh-TW is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.171-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.743-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.974-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-zh-TW is installed" test_ref="oval:org.mitre.oval:tst:4477"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8998" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-da is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-da"/>
        <description>Package OpenOffice_org-da is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:47">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.780-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.683-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.904-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-da is installed" test_ref="oval:org.mitre.oval:tst:4791"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8997" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-galleries is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-galleries"/>
        <description>Package OpenOffice_org-galleries is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:33">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.255-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.625-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-galleries is installed" test_ref="oval:org.mitre.oval:tst:4799"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8995" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-zh-CN is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-zh-CN"/>
        <description>Package OpenOffice_org-zh-CN is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:33">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.712-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.565-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-zh-CN is installed" test_ref="oval:org.mitre.oval:tst:4875"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8987" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ja is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ja"/>
        <description>Package OpenOffice_org-ja is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:07">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.622-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.500-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ja is installed" test_ref="oval:org.mitre.oval:tst:4671"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8974" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-af is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-af"/>
        <description>Package OpenOffice_org-af is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:15">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.334-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.440-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-af is installed" test_ref="oval:org.mitre.oval:tst:4549"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8958" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-en is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-en"/>
        <description>Package OpenOffice_org1-en is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.195-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.381-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-en is installed" test_ref="oval:org.mitre.oval:tst:4947"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8915" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ca is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ca"/>
        <description>Package OpenOffice_org1-ca is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:02.928-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.325-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.444-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ca is installed" test_ref="oval:org.mitre.oval:tst:4574"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8914" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-gnome is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-gnome"/>
        <description>Package OpenOffice_org-gnome is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:37">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.305-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.260-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.371-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-gnome is installed" test_ref="oval:org.mitre.oval:tst:4675"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8906" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-pt is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-pt"/>
        <description>Package OpenOffice_org1-pt is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.866-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.205-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-pt is installed" test_ref="oval:org.mitre.oval:tst:5167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8903" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-sk is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-sk"/>
        <description>Package OpenOffice_org1-sk is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.950-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.152-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-sk is installed" test_ref="oval:org.mitre.oval:tst:4843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8892" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-hunspell is installed</title>
        <affected family="unix">
          <platform>SUSE Linux 10.0</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-hunspell"/>
        <description>Package OpenOffice_org-hunspell is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:56">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.529-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.099-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-hunspell is installed" test_ref="oval:org.mitre.oval:tst:4443"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8887" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ca is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ca"/>
        <description>Package OpenOffice_org-ca is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:33">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.567-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.040-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ca is installed" test_ref="oval:org.mitre.oval:tst:4866"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8886" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-pt-BR is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-pt-BR"/>
        <description>Package OpenOffice_org-pt-BR is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:07">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.237-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.971-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.067-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-pt-BR is installed" test_ref="oval:org.mitre.oval:tst:4754"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8882" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-pa-IN is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-pa-IN"/>
        <description>Package OpenOffice_org-pa-IN is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:54">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.083-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.910-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:38.002-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-pa-IN is installed" test_ref="oval:org.mitre.oval:tst:4615"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8865" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org"/>
        <description>Package OpenOffice_org is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:09">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.247-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.849-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.936-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org is installed" test_ref="oval:org.mitre.oval:tst:4677"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8860" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-sv is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-sv"/>
        <description>Package OpenOffice_org-sv is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:53">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.506-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.789-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-sv is installed" test_ref="oval:org.mitre.oval:tst:4550"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8829" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-en-GB is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-en-GB"/>
        <description>Package OpenOffice_org-en-GB is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:11">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.980-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.732-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.798-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-en-GB is installed" test_ref="oval:org.mitre.oval:tst:4815"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8815" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-fi is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-fi"/>
        <description>Package OpenOffice_org1-fi is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.353-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.680-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-fi is installed" test_ref="oval:org.mitre.oval:tst:5169"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8804" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-nb is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-nb"/>
        <description>Package OpenOffice_org-nb is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:39">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.901-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.619-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-nb is installed" test_ref="oval:org.mitre.oval:tst:5021"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8801" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-el is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-el"/>
        <description>Package OpenOffice_org-el is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:07">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.924-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.553-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.610-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-el is installed" test_ref="oval:org.mitre.oval:tst:4238"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8799" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-pl is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-pl"/>
        <description>Package OpenOffice_org-pl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:59">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.128-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.489-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.533-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-pl is installed" test_ref="oval:org.mitre.oval:tst:4556"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8777" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-ar is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-ar"/>
        <description>Package OpenOffice_org1-ar is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:02.882-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.436-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.454-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-ar is installed" test_ref="oval:org.mitre.oval:tst:4273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8774" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-kde is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-kde"/>
        <description>Package OpenOffice_org1-kde is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.694-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.383-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-kde is installed" test_ref="oval:org.mitre.oval:tst:4748"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8773" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-sl is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-sl"/>
        <description>Package OpenOffice_org1-sl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.994-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.330-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-sl is installed" test_ref="oval:org.mitre.oval:tst:5084"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8733" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-cs is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-cs"/>
        <description>Package OpenOffice_org-cs is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:39">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.637-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.268-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.259-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-cs is installed" test_ref="oval:org.mitre.oval:tst:4348"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8715" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-hr is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-hr"/>
        <description>Package OpenOffice_org-hr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:49">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.414-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.205-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-hr is installed" test_ref="oval:org.mitre.oval:tst:5026"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8707" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-tr is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-tr"/>
        <description>Package OpenOffice_org-tr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:15">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.558-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.146-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-tr is installed" test_ref="oval:org.mitre.oval:tst:4210"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8705" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-es is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-es"/>
        <description>Package OpenOffice_org1-es is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.244-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.092-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:37.017-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-es is installed" test_ref="oval:org.mitre.oval:tst:4329"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8691" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-it is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-it"/>
        <description>Package OpenOffice_org1-it is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.599-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:44.037-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.952-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-it is installed" test_ref="oval:org.mitre.oval:tst:4212"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8688" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-de is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-de"/>
        <description>Package OpenOffice_org-de is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:51">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.859-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.969-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-de is installed" test_ref="oval:org.mitre.oval:tst:5008"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8681" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-et is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-et"/>
        <description>Package OpenOffice_org1-et is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.304-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.915-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-et is installed" test_ref="oval:org.mitre.oval:tst:5094"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8678" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-et is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-et"/>
        <description>Package OpenOffice_org-et is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.091-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.853-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.752-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-et is installed" test_ref="oval:org.mitre.oval:tst:5033"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8672" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-fr is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-fr"/>
        <description>Package OpenOffice_org1-fr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.406-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.798-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-fr is installed" test_ref="oval:org.mitre.oval:tst:5105"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8664" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-pt is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-pt"/>
        <description>Package OpenOffice_org-pt is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:03">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.180-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.735-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.537-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-pt is installed" test_ref="oval:org.mitre.oval:tst:4724"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8663" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ar is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ar"/>
        <description>Package OpenOffice_org-ar is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.415-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.675-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.472-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ar is installed" test_ref="oval:org.mitre.oval:tst:4205"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8652" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-el is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-el"/>
        <description>Package OpenOffice_org1-el is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.150-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.535-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.317-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-el is installed" test_ref="oval:org.mitre.oval:tst:4345"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8611" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-nl is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-nl"/>
        <description>Package OpenOffice_org-nl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:42">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.942-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.477-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.251-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-nl is installed" test_ref="oval:org.mitre.oval:tst:4956"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8604" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-zh-CN is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-zh-CN"/>
        <description>Package OpenOffice_org1-zh-CN is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.127-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.426-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-zh-CN is installed" test_ref="oval:org.mitre.oval:tst:5187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8583" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-es is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-es"/>
        <description>Package OpenOffice_org-es is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:15">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.035-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.365-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-es is installed" test_ref="oval:org.mitre.oval:tst:4751"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8541" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-officebean is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-officebean"/>
        <description>Package OpenOffice_org-officebean is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:50">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.039-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.307-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-officebean is installed" test_ref="oval:org.mitre.oval:tst:5132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8533" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-de is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-de"/>
        <description>Package OpenOffice_org1-de is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.092-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.254-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-de is installed" test_ref="oval:org.mitre.oval:tst:4764"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8502" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-pl is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-pl"/>
        <description>Package OpenOffice_org1-pl is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.818-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.200-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-pl is installed" test_ref="oval:org.mitre.oval:tst:4319"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8501" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-nn is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-nn"/>
        <description>Package OpenOffice_org-nn is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:46">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.988-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.144-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.856-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-nn is installed" test_ref="oval:org.mitre.oval:tst:4734"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8477" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-xh is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-xh"/>
        <description>Package OpenOffice_org-xh is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:29">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.658-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.087-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.791-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-xh is installed" test_ref="oval:org.mitre.oval:tst:4357"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8451" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-fi is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-fi"/>
        <description>Package OpenOffice_org-fi is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:22">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.142-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.025-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-fi is installed" test_ref="oval:org.mitre.oval:tst:4254"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8432" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-be-BY is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-be-BY"/>
        <description>Package OpenOffice_org-be-BY is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:25">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.465-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.964-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-be-BY is installed" test_ref="oval:org.mitre.oval:tst:4526"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8403" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-bg is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-bg"/>
        <description>Package OpenOffice_org-bg is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:29">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.517-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.902-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-bg is installed" test_ref="oval:org.mitre.oval:tst:4461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8389" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ru is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ru"/>
        <description>Package OpenOffice_org-ru is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:24">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.287-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.844-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ru is installed" test_ref="oval:org.mitre.oval:tst:4980"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8380" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-hu is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-hu"/>
        <description>Package OpenOffice_org1-hu is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.557-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.794-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-hu is installed" test_ref="oval:org.mitre.oval:tst:4532"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8357" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-cs is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-cs"/>
        <description>Package OpenOffice_org1-cs is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:02.976-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.691-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-cs is installed" test_ref="oval:org.mitre.oval:tst:4711"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8352" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-ko is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-ko"/>
        <description>Package OpenOffice_org-ko is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.726-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.634-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-ko is installed" test_ref="oval:org.mitre.oval:tst:4941"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8342" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-gnome is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-gnome"/>
        <description>Package OpenOffice_org1-gnome is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.454-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.582-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-gnome is installed" test_ref="oval:org.mitre.oval:tst:4430"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8341" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-gu-IN is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-gu-IN"/>
        <description>Package OpenOffice_org-gu-IN is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:42">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.364-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.525-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:35.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-gu-IN is installed" test_ref="oval:org.mitre.oval:tst:4522"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8329" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-cy is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-cy"/>
        <description>Package OpenOffice_org-cy is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:58:44">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.695-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.359-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-cy is installed" test_ref="oval:org.mitre.oval:tst:5190"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8310" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-tr is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-tr"/>
        <description>Package OpenOffice_org1-tr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:04.083-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.307-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-tr is installed" test_ref="oval:org.mitre.oval:tst:4961"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8308" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1-da is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1-da"/>
        <description>Package OpenOffice_org1-da is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:03.025-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.256-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1-da is installed" test_ref="oval:org.mitre.oval:tst:5012"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8288" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-vi is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-vi"/>
        <description>Package OpenOffice_org-vi is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:23">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.610-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.202-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-vi is installed" test_ref="oval:org.mitre.oval:tst:5155"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:828" version="2" class="vulnerability">
      <metadata>
        <title>mod_python Web Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mod_python</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973"/>
        <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.737-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_python version is less than 3.0.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:1612"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8272" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in rm(1) may Lead to Unauthorized Deletion of Files or Directories</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0895"/>
        <description>Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-06T11:50:11.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-08T21:33:23.977-04:00">DRAFT</status_change>
            <status_change date="2007-08-23T14:55:19.959-04:00">INTERIM</status_change>
            <status_change date="2007-09-10T14:45:27.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 124969-01 or later installed" test_ref="oval:org.mitre.oval:tst:4414" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 123372-02 or later installed" test_ref="oval:org.mitre.oval:tst:4946" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124244-01 or later installed" test_ref="oval:org.mitre.oval:tst:4215" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 124970-01 or later installed" test_ref="oval:org.mitre.oval:tst:4906" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 123373-02 or later installed" test_ref="oval:org.mitre.oval:tst:5133" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124245-01 or later installed" test_ref="oval:org.mitre.oval:tst:4576" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:827" version="2" class="vulnerability">
      <metadata>
        <title>Samba mksmboasswd Disabled Account Creation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Samba 3.0.0 and 3.0.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0082"/>
        <description>The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.833-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 3.0.2-6.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1613"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8269" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-zu is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-zu"/>
        <description>Package OpenOffice_org-zu is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:02:42">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.813-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:41.108-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.519-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-zu is installed" test_ref="oval:org.mitre.oval:tst:4496"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8264" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org1 is installed</title>
        <affected family="unix">
          <platform>SUSE Linux Professional 9.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org1"/>
        <description>Package OpenOffice_org1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:09:19">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:02.829-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:41.060-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:suse_linux:9.3::pro</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org1 is installed" test_ref="oval:org.mitre.oval:tst:4214"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:826" version="2" class="vulnerability">
      <metadata>
        <title>RedHat Enterprise 3 Code Execution and DoS Vulnerabilities in PWLib</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>PWLib</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097"/>
        <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Added a program_name element to rlt-217">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:26.501-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.025-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pwlib version is less than 1.4.7-7.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1614"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="a program is listening on TCP or UDP port 1720" negate="false" test_ref="oval:org.mitre.oval:tst:2320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:825" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Linux Kernel do_mremap Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mremap</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077"/>
        <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.934-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="kernel version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1617"/>
          <criterion comment="kernel-smp version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1616"/>
          <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8244" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-sk is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-sk"/>
        <description>Package OpenOffice_org-sk is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:01:38">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:06.342-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:40.996-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.387-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-sk is installed" test_ref="oval:org.mitre.oval:tst:4739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:823" version="2" class="vulnerability">
      <metadata>
        <title>Konqueror Cookie Access Restrictions Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0592"/>
        <description>Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.940-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1-13" negate="false" test_ref="oval:org.mitre.oval:tst:1618"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/konqueror is executable">
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2655"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2654"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8228" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-hu is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-hu"/>
        <description>Package OpenOffice_org-hu is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:53">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.468-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:40.941-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-hu is installed" test_ref="oval:org.mitre.oval:tst:4235"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8222" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-mono is installed</title>
        <affected family="unix">
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-mono"/>
        <description>Package OpenOffice_org-mono is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T22:00:35">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.845-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:40.881-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.249-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-mono is installed" test_ref="oval:org.mitre.oval:tst:4809"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:822" version="2" class="vulnerability">
      <metadata>
        <title>Midnight Commander vfs_s_resolve_symlink BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Midnight Commander</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1023"/>
        <description>Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.070-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.376-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mc version is less than 4.6.0-7.9" negate="false" test_ref="oval:org.mitre.oval:tst:1622"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mc is executable">
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1621"/>
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1620"/>
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8215" version="1" class="inventory">
      <metadata>
        <title>Package OpenOffice_org-fr is installed</title>
        <affected family="unix">
          <platform>Novell Linux Desktop 9</platform>
          <platform>openSUSE 10.2</platform>
          <platform>SUSE Linux 10.0</platform>
          <platform>SUSE Linux 10.1</platform>
          <platform>SUSE Linux Enterprise Desktop 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:novell:openoffice_org-fr"/>
        <description>Package OpenOffice_org-fr is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-07T21:59:29">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </submitted>
            <status_change date="2007-08-01T22:23:05.202-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:40.821-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:33.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:novell:linux_desktop:9</cpe>
            <cpe>cpe:/o:novell:opensuse:10.2</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.0</cpe>
            <cpe>cpe:/o:novell:suse_linux:10.1</cpe>
            <cpe>cpe:/o:novell:suse_linux_enterprise:10::desktop</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="OpenOffice_org-fr is installed" test_ref="oval:org.mitre.oval:tst:4518"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:821" version="2" class="vulnerability">
      <metadata>
        <title>slocate Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>slocate</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0848"/>
        <description>Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.635-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="slocate version is less than 2.7-2" negate="false" test_ref="oval:org.mitre.oval:tst:1625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/bin/slocate is setgid">
            <criterion comment="/usr/bin/slocate is setgid" negate="false" test_ref="oval:org.mitre.oval:tst:1624"/>
            <criterion comment="/usr/bin/slocate is setgid" negate="false" test_ref="oval:org.mitre.oval:tst:1623"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:820" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic directIM Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0008"/>
        <description>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.269-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.989-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:82" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft RPC Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0509"/>
        <description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-04-07T12:00:00.000-04:00" comment="modified wft-225 - correct literal component in file path. Added '\' to the start of the literal string.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-04-11T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-12T12:00:00.000-04:00" comment="modified wft-89 - wft-89 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T01:26:00.000-04:00" comment="modified wft-89 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="the version of ssmsrp70.dll is less than 2000.80.213.0" negate="false" test_ref="oval:org.mitre.oval:tst:2968"/>
        <criterion comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" negate="false" test_ref="oval:org.mitre.oval:tst:2967"/>
        <criterion comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" negate="true" test_ref="oval:org.mitre.oval:tst:2966"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:819" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic Extract Info Field Function BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0007"/>
        <description>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.253-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:818" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic BO Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0006"/>
        <description>Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:36.164-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:817" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox and Mozilla Shared Object Code Execution</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2270"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:816" version="2" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:815" version="2" class="vulnerability">
      <metadata>
        <title>Mailman Cross-site Scripting Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mailman</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0992" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0992"/>
        <description>Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.512-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.374-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mailman version is less than 2.1.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:1631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:813" version="2" class="vulnerability">
      <metadata>
        <title>Mailman Cross-site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mailman</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0965"/>
        <description>Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.431-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.077-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mailman version is less than 2.1.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:1631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8127" version="3" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing on Double Byte Character Set Systems Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0844"/>
        <description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T05:13:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:59.342-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:00.949-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="true" test_ref="oval:org.mitre.oval:tst:519"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:812" version="4" class="vulnerability">
      <metadata>
        <title>Outlook Express 6 (S03-Gold) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:58:00.007-05:00">ACCEPTED</status_change>
            <modified comment="Removed unneeded ste:2282 from tst:2437. Deprecated ste:2282 since it is no longer used." date="2007-01-12T07:06:00.595-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-12T07:08:54.564-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:00.679-05:00">ACCEPTED</status_change>
            <modified comment="Changed affected platform to Microsoft Windows Server 2003. Implemented by Jon Baker of the MITRE Corporation." date="2007-03-14T20:54:00.610-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-14T20:56:21.701-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:28.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Outlook Express 6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2663" negate="false" test_ref="oval:org.mitre.oval:tst:1632"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:811" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mutt BO in Index Menu</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0078"/>
        <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:31.712-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:54.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-3.3" negate="false" test_ref="oval:org.mitre.oval:tst:1634"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:810" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 netpbm File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>netpbm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924"/>
        <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:26.732-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:49.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="netpbm version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1637"/>
            <criterion comment="netpbm-devel version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1636"/>
            <criterion comment="netpbm-progs version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1635"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable configuration">
            <criteria operator="OR" comment="/usr/bin/411toppm is executable">
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2316"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2315"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2314"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/asciitopgm is executable">
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2313"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2312"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2311"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/atktopbm is executable">
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2310"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2309"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2308"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bioradtopgm is executable">
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2307"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2306"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2305"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bmptoppm is executable">
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2304"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2303"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2302"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/brushtopbm is executable">
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2301"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2300"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2299"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/cmuwmtopbm is executable">
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2298"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2297"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2296"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/eyuvtoppm is executable">
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2295"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2294"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2293"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fiascotopnm is executable">
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2292"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2291"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2290"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fitstopnm is executable">
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2289"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2288"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2287"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fstopgm is executable">
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2286"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2285"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2284"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/g3topbm is executable">
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2283"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2282"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2281"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopbm is executable">
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2280"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2279"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2278"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopnm is executable">
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2277"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2276"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2275"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/giftopnm is executable">
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2274"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2273"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2272"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gouldtoppm is executable">
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2271"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2270"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2269"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hipstopgm is executable">
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2268"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2267"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2266"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hpcdtoppm is executable">
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2265"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2264"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2263"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/icontopbm is executable">
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2262"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2261"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2260"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ilbmtoppm is executable">
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2259"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2258"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2257"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/imgtoppm is executable">
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2256"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2255"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2254"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/jpegtopnm is executable">
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2253"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2252"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2251"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/leaftoppm is executable">
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2250"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2249"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2248"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/lispmtopgm is executable">
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2247"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2246"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2245"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/macptopbm is executable">
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2244"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2243"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2242"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mdatopbm is executable">
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2241"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2240"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2239"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mgrtopbm is executable">
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2238"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2237"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2236"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mtvtoppm is executable">
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2235"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2234"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2233"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/neotoppm is executable">
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2232"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2231"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2230"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/palmtopnm is executable">
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2229"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2228"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2227"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamchannel is executable">
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2226"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2225"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2224"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamcut is executable">
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2223"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2222"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2221"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamdeinterlace is executable">
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2220"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2219"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2218"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamfile is executable">
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2217"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2216"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2215"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamoil is executable">
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2214"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2213"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2212"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamstretch is executable">
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2211"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2210"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2209"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamtopnm is executable">
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2208"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2207"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2206"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmclean is executable">
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2205"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2204"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2203"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmlife is executable">
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2202"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2201"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2200"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmake is executable">
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2199"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2198"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2197"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmask is executable">
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2196"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2195"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2194"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpage is executable">
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2193"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2192"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2191"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpscale is executable">
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2190"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2189"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2188"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmreduce is executable">
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2187"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2186"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2185"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtext is executable">
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2184"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2183"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2182"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto10x is executable">
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2181"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2180"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2179"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto4425 is executable">
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2178"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2177"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2176"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoascii is executable">
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2175"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2174"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2173"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoatk is executable">
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2172"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2171"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2170"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtobbnbg is executable">
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2169"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2168"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2167"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtocmuwm is executable">
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2166"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2165"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2164"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepsi is executable">
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2163"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2162"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2161"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepson is executable">
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2160"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2159"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2158"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtog3 is executable">
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2157"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2156"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2155"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogem is executable">
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2154"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2153"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2152"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogo is executable">
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2151"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2150"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2149"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoicon is executable">
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2148"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2147"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2146"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolj is executable">
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2145"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2144"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2143"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoln03 is executable">
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2142"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2141"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2140"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolps is executable">
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2139"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2138"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2137"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomacp is executable">
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2136"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2135"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2134"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomda is executable">
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2133"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2132"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2131"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomgr is executable">
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2130"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2129"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2128"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtonokia is executable">
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2127"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2126"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2125"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopgm is executable">
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2124"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2123"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2122"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopi3 is executable">
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2121"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2120"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2119"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopk is executable">
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2118"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2117"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2116"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoplot is executable">
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2115"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2114"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2113"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoppa is executable">
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2112"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2111"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2110"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopsg3 is executable">
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2109"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2108"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2107"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoptx is executable">
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2106"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2105"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2104"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtowbmp is executable">
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2103"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2102"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2101"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtox10bm is executable">
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2100"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2099"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2098"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoxbm is executable">
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2097"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2096"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2095"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoybm is executable">
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2094"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2093"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2092"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtozinc is executable">
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2091"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2090"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2089"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmupc is executable">
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2088"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2087"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2086"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pcxtoppm is executable">
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2085"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2084"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2083"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmbentley is executable">
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2082"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2081"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2080"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmcrater is executable">
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2079"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2078"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2077"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmedge is executable">
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2076"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2075"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2074"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmenhance is executable">
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2073"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2072"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2071"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmhist is executable">
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2070"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2069"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2068"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmkernel is executable">
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2067"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2066"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2065"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnoise is executable">
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2064"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2063"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2062"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnorm is executable">
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2061"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2060"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2059"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmoil is executable">
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2058"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2057"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2056"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmramp is executable">
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2055"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2054"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2053"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmslice is executable">
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2052"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2051"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2050"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtexture is executable">
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2049"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2048"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2047"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtofs is executable">
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2046"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2045"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2044"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtolispm is executable">
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2043"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2042"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2041"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtopbm is executable">
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2040"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2039"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2038"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtoppm is executable">
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2037"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2036"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2035"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi1toppm is executable">
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2034"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2033"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2032"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi3topbm is executable">
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2031"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2030"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2029"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pjtoppm is executable">
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2028"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2027"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2026"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pktopbm is executable">
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2025"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2024"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2023"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pngtopnm is executable">
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2022"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2021"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2020"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmalias is executable">
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2019"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2018"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2017"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmarith is executable">
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2016"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2015"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2014"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcat is executable">
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2013"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2012"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2011"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcolormap is executable">
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2010"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2009"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2008"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcomp is executable">
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2007"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2006"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2005"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmconvol is executable">
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2004"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2003"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2002"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcrop is executable">
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2001"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2000"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1999"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcut is executable">
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1998"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1997"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1996"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmdepth is executable">
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1995"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1994"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1993"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmenlarge is executable">
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1992"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1991"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1990"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmfile is executable">
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1989"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1988"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1987"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmflip is executable">
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1986"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1985"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1984"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmgamma is executable">
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1983"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1982"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1981"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhisteq is executable">
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1980"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1979"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1978"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhistmap is executable">
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1977"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1976"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1975"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminterp is executable">
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1974"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1973"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1972"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminvert is executable">
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1971"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1970"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1969"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmmontage is executable">
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1968"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1967"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1966"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnlfilt is executable">
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1965"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1964"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1963"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnoraw is executable">
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1962"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1961"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1960"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpad is executable">
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1959"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1958"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1957"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpaste is executable">
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1956"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1955"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1954"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpsnr is executable">
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1953"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1952"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1951"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmremap is executable">
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1950"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1949"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1948"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmrotate is executable">
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1947"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1946"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1945"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscale is executable">
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1944"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1943"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1942"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopict is executable">
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1941"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1940"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1939"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopj is executable">
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1938"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1937"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1936"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopjxl is executable">
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1935"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1934"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1933"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopuzz is executable">
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1932"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1931"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1930"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtorgb3 is executable">
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1929"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1928"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1927"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtosixel is executable">
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1926"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1925"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1924"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtotga is executable">
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1923"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1922"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1921"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtouil is executable">
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1920"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1919"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1918"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtowinicon is executable">
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1917"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1916"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1915"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoxpm is executable">
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1914"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1913"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1912"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuv is executable">
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1911"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1910"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1909"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuvsplit is executable">
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1908"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1907"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1906"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtv is executable">
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1905"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1904"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1903"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/psidtopgm is executable">
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1902"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1901"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1900"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pstopnm is executable">
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1899"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1898"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1897"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/qrttoppm is executable">
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1896"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1895"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1894"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rasttopnm is executable">
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1893"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1892"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1891"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtopgm is executable">
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1890"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1889"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1888"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtoppm is executable">
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1887"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1886"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1885"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rgb3toppm is executable">
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1884"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1883"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1882"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rletopnm is executable">
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1881"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1880"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1879"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sbigtopgm is executable">
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1878"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1877"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1876"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sgitopnm is executable">
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1875"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1874"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1873"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sirtopnm is executable">
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1872"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1871"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1870"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sldtoppm is executable">
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1869"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1868"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1867"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spctoppm is executable">
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1866"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1865"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1864"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spottopgm is executable">
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1863"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1862"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1861"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sputoppm is executable">
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1860"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1859"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1858"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tgatoppm is executable">
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1857"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1856"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1855"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/thinkjettopbm is executable">
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1854"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1853"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1852"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tifftopnm is executable">
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1851"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1850"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1849"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/wbmptopbm is executable">
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1848"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1847"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1846"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/winicontoppm is executable">
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1845"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1844"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1843"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xbmtopbm is executable">
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1842"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1841"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1840"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ximtoppm is executable">
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1839"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1838"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1837"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xpmtoppm is executable">
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1836"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1835"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1834"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xvminitoppm is executable">
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1833"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1832"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1831"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xwdtopnm is executable">
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1830"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1829"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1828"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ybmtopbm is executable">
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1827"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1826"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1825"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvsplittoppm is executable">
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1824"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1823"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1822"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvtoppm is executable">
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1821"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1820"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1819"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/zeisstopnm is executable">
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1818"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1817"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1816"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscalefixed is executable">
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1815"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1814"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1813"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmshear is executable">
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1812"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1811"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1810"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsmooth is executable">
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1809"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1808"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1807"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsplit is executable">
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1806"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1805"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1804"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtile is executable">
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1803"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1802"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1801"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoddif is executable">
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1800"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1799"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1798"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofiasco is executable">
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1797"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1796"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1795"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofits is executable">
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1794"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1793"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1792"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtojpeg is executable">
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1791"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1790"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1789"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopalm is executable">
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1788"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1787"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1786"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoplainpnm is executable">
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1785"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1784"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1783"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopng is executable">
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1782"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1781"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1780"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtops is executable">
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1779"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1778"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1777"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorast is executable">
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1776"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1775"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1774"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorle is executable">
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1773"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1772"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1771"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosgi is executable">
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1770"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1769"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1768"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosir is executable">
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1767"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1766"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1765"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiff is executable">
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1764"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1763"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1762"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiffcmyk is executable">
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1761"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1760"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1759"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoxwd is executable">
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1758"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1757"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1756"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppm3d is executable">
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1755"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1754"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1753"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmbrighten is executable">
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1752"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1751"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1750"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmchange is executable">
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1749"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1748"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1747"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcie is executable">
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1746"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1745"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1744"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolormask is executable">
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1743"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1742"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1741"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolors is executable">
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1740"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1739"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1738"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdim is executable">
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1737"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1736"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1735"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdist is executable">
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1734"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1733"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1732"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdither is executable">
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1731"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1730"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1729"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmflash is executable">
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1728"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1727"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1726"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmforge is executable">
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1725"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1724"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1723"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmhist is executable">
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1722"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1721"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1720"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmlabel is executable">
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1719"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1718"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1717"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmake is executable">
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1716"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1715"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1714"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmix is executable">
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1713"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1712"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1711"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmnorm is executable">
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1710"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1709"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1708"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmntsc is executable">
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1707"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1706"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1705"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmpat is executable">
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1704"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1703"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1702"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmquant is executable">
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1701"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1700"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1699"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmqvga is executable">
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1698"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1697"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1696"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmrelief is executable">
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1695"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1694"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1693"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmshift is executable">
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1692"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1691"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1690"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmspread is executable">
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1689"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1688"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1687"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoacad is executable">
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1686"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1685"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1684"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtobmp is executable">
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1683"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1682"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1681"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoeyuv is executable">
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1680"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1679"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1678"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtogif is executable">
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1677"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1676"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1675"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoicr is executable">
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1674"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1673"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1672"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoilbm is executable">
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1671"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1670"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1669"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtojpeg is executable">
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1668"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1667"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1666"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoleaf is executable">
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1665"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1664"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1663"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtolj is executable">
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1662"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1661"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1660"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtomitsu is executable">
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1659"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1658"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1657"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtompeg is executable">
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1656"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1655"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1654"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoneo is executable">
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1653"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1652"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1651"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopcx is executable">
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1650"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1649"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1648"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopgm is executable">
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1647"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1646"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1645"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopi1 is executable">
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1644"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1643"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1642"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:81" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS HTTP Error Page Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0148"/>
        <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:809" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Font File Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106"/>
        <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:21.877-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.539-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:808" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 XBL Script Security Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2261"/>
        <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8077" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0, SP1 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:03.976-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:00.405-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:807" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat XFree86 Buffer Overflow in ReadFontAlias II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084"/>
        <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.326-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:806" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat XFree86 Buffer Overflow in ReadFontAlias</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083"/>
        <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.593-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:805" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:54:00.000-04:00" comment="modified wft-95 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:22:33.027-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:00.077-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.118" negate="false" test_ref="oval:org.mitre.oval:tst:2572"/>
          <criterion comment="the patch q832894 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2571"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:804" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat netpbm File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>netpbm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924"/>
        <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:00.100-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:42.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="netpbm version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2319"/>
            <criterion comment="netpbm-devel version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2318"/>
            <criterion comment="netpbm-progs version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2317"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable configuration">
            <criteria operator="OR" comment="/usr/bin/411toppm is executable">
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2316"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2315"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2314"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/asciitopgm is executable">
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2313"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2312"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2311"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/atktopbm is executable">
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2310"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2309"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2308"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bioradtopgm is executable">
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2307"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2306"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2305"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bmptoppm is executable">
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2304"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2303"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2302"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/brushtopbm is executable">
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2301"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2300"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2299"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/cmuwmtopbm is executable">
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2298"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2297"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2296"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/eyuvtoppm is executable">
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2295"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2294"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2293"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fiascotopnm is executable">
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2292"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2291"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2290"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fitstopnm is executable">
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2289"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2288"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2287"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fstopgm is executable">
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2286"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2285"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2284"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/g3topbm is executable">
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2283"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2282"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2281"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopbm is executable">
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2280"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2279"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2278"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopnm is executable">
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2277"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2276"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2275"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/giftopnm is executable">
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2274"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2273"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2272"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gouldtoppm is executable">
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2271"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2270"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2269"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hipstopgm is executable">
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2268"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2267"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2266"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hpcdtoppm is executable">
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2265"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2264"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2263"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/icontopbm is executable">
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2262"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2261"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2260"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ilbmtoppm is executable">
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2259"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2258"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2257"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/imgtoppm is executable">
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2256"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2255"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2254"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/jpegtopnm is executable">
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2253"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2252"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2251"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/leaftoppm is executable">
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2250"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2249"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2248"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/lispmtopgm is executable">
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2247"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2246"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2245"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/macptopbm is executable">
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2244"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2243"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2242"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mdatopbm is executable">
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2241"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2240"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2239"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mgrtopbm is executable">
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2238"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2237"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2236"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mtvtoppm is executable">
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2235"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2234"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2233"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/neotoppm is executable">
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2232"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2231"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2230"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/palmtopnm is executable">
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2229"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2228"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2227"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamchannel is executable">
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2226"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2225"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2224"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamcut is executable">
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2223"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2222"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2221"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamdeinterlace is executable">
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2220"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2219"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2218"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamfile is executable">
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2217"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2216"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2215"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamoil is executable">
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2214"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2213"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2212"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamstretch is executable">
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2211"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2210"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2209"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamtopnm is executable">
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2208"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2207"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2206"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmclean is executable">
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2205"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2204"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2203"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmlife is executable">
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2202"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2201"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2200"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmake is executable">
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2199"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2198"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2197"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmask is executable">
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2196"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2195"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2194"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpage is executable">
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2193"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2192"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2191"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpscale is executable">
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2190"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2189"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2188"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmreduce is executable">
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2187"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2186"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2185"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtext is executable">
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2184"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2183"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2182"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto10x is executable">
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2181"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2180"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2179"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto4425 is executable">
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2178"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2177"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2176"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoascii is executable">
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2175"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2174"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2173"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoatk is executable">
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2172"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2171"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2170"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtobbnbg is executable">
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2169"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2168"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2167"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtocmuwm is executable">
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2166"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2165"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2164"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepsi is executable">
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2163"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2162"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2161"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepson is executable">
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2160"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2159"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2158"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtog3 is executable">
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2157"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2156"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2155"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogem is executable">
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2154"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2153"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2152"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogo is executable">
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2151"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2150"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2149"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoicon is executable">
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2148"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2147"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2146"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolj is executable">
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2145"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2144"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2143"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoln03 is executable">
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2142"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2141"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2140"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolps is executable">
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2139"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2138"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2137"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomacp is executable">
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2136"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2135"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2134"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomda is executable">
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2133"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2132"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2131"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomgr is executable">
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2130"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2129"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2128"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtonokia is executable">
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2127"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2126"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2125"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopgm is executable">
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2124"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2123"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2122"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopi3 is executable">
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2121"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2120"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2119"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopk is executable">
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2118"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2117"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2116"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoplot is executable">
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2115"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2114"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2113"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoppa is executable">
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2112"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2111"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2110"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopsg3 is executable">
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2109"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2108"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2107"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoptx is executable">
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2106"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2105"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2104"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtowbmp is executable">
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2103"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2102"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2101"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtox10bm is executable">
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2100"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2099"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2098"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoxbm is executable">
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2097"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2096"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2095"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoybm is executable">
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2094"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2093"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2092"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtozinc is executable">
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2091"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2090"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2089"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmupc is executable">
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2088"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2087"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2086"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pcxtoppm is executable">
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2085"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2084"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2083"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmbentley is executable">
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2082"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2081"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2080"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmcrater is executable">
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2079"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2078"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2077"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmedge is executable">
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2076"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2075"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2074"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmenhance is executable">
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2073"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2072"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2071"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmhist is executable">
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2070"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2069"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2068"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmkernel is executable">
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2067"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2066"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2065"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnoise is executable">
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2064"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2063"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2062"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnorm is executable">
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2061"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2060"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2059"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmoil is executable">
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2058"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2057"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2056"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmramp is executable">
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2055"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2054"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2053"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmslice is executable">
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2052"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2051"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2050"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtexture is executable">
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2049"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2048"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2047"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtofs is executable">
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2046"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2045"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2044"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtolispm is executable">
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2043"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2042"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2041"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtopbm is executable">
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2040"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2039"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2038"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtoppm is executable">
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2037"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2036"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2035"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi1toppm is executable">
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2034"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2033"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2032"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi3topbm is executable">
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2031"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2030"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2029"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pjtoppm is executable">
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2028"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2027"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2026"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pktopbm is executable">
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2025"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2024"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2023"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pngtopnm is executable">
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2022"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2021"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2020"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmalias is executable">
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2019"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2018"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2017"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmarith is executable">
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2016"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2015"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2014"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcat is executable">
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2013"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2012"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2011"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcolormap is executable">
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2010"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2009"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2008"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcomp is executable">
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2007"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2006"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2005"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmconvol is executable">
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2004"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2003"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2002"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcrop is executable">
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2001"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2000"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1999"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcut is executable">
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1998"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1997"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1996"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmdepth is executable">
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1995"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1994"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1993"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmenlarge is executable">
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1992"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1991"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1990"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmfile is executable">
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1989"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1988"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1987"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmflip is executable">
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1986"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1985"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1984"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmgamma is executable">
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1983"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1982"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1981"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhisteq is executable">
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1980"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1979"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1978"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhistmap is executable">
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1977"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1976"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1975"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminterp is executable">
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1974"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1973"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1972"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminvert is executable">
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1971"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1970"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1969"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmmontage is executable">
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1968"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1967"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1966"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnlfilt is executable">
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1965"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1964"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1963"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnoraw is executable">
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1962"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1961"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1960"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpad is executable">
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1959"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1958"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1957"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpaste is executable">
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1956"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1955"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1954"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpsnr is executable">
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1953"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1952"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1951"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmremap is executable">
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1950"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1949"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1948"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmrotate is executable">
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1947"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1946"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1945"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscale is executable">
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1944"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1943"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1942"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopict is executable">
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1941"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1940"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1939"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopj is executable">
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1938"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1937"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1936"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopjxl is executable">
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1935"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1934"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1933"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopuzz is executable">
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1932"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1931"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1930"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtorgb3 is executable">
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1929"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1928"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1927"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtosixel is executable">
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1926"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1925"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1924"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtotga is executable">
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1923"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1922"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1921"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtouil is executable">
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1920"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1919"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1918"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtowinicon is executable">
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1917"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1916"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1915"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoxpm is executable">
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1914"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1913"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1912"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuv is executable">
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1911"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1910"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1909"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuvsplit is executable">
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1908"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1907"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1906"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtv is executable">
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1905"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1904"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1903"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/psidtopgm is executable">
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1902"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1901"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1900"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pstopnm is executable">
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1899"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1898"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1897"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/qrttoppm is executable">
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1896"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1895"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1894"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rasttopnm is executable">
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1893"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1892"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1891"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtopgm is executable">
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1890"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1889"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1888"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtoppm is executable">
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1887"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1886"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1885"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rgb3toppm is executable">
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1884"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1883"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1882"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rletopnm is executable">
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1881"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1880"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1879"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sbigtopgm is executable">
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1878"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1877"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1876"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sgitopnm is executable">
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1875"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1874"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1873"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sirtopnm is executable">
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1872"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1871"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1870"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sldtoppm is executable">
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1869"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1868"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1867"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spctoppm is executable">
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1866"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1865"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1864"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spottopgm is executable">
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1863"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1862"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1861"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sputoppm is executable">
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1860"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1859"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1858"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tgatoppm is executable">
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1857"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1856"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1855"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/thinkjettopbm is executable">
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1854"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1853"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1852"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tifftopnm is executable">
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1851"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1850"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1849"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/wbmptopbm is executable">
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1848"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1847"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1846"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/winicontoppm is executable">
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1845"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1844"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1843"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xbmtopbm is executable">
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1842"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1841"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1840"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ximtoppm is executable">
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1839"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1838"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1837"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xpmtoppm is executable">
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1836"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1835"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1834"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xvminitoppm is executable">
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1833"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1832"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1831"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xwdtopnm is executable">
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1830"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1829"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1828"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ybmtopbm is executable">
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1827"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1826"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1825"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvsplittoppm is executable">
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1824"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1823"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1822"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvtoppm is executable">
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1821"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1820"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1819"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/zeisstopnm is executable">
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1818"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1817"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1816"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscalefixed is executable">
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1815"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1814"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1813"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmshear is executable">
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1812"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1811"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1810"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsmooth is executable">
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1809"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1808"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1807"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsplit is executable">
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1806"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1805"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1804"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtile is executable">
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1803"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1802"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1801"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoddif is executable">
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1800"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1799"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1798"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofiasco is executable">
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1797"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1796"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1795"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofits is executable">
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1794"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1793"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1792"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtojpeg is executable">
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1791"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1790"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1789"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopalm is executable">
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1788"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1787"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1786"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoplainpnm is executable">
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1785"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1784"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1783"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopng is executable">
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1782"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1781"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1780"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtops is executable">
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1779"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1778"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1777"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorast is executable">
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1776"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1775"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1774"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorle is executable">
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1773"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1772"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1771"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosgi is executable">
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1770"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1769"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1768"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosir is executable">
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1767"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1766"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1765"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiff is executable">
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1764"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1763"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1762"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiffcmyk is executable">
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1761"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1760"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1759"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoxwd is executable">
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1758"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1757"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1756"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppm3d is executable">
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1755"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1754"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1753"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmbrighten is executable">
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1752"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1751"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1750"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmchange is executable">
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1749"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1748"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1747"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcie is executable">
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1746"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1745"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1744"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolormask is executable">
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1743"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1742"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1741"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolors is executable">
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1740"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1739"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1738"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdim is executable">
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1737"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1736"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1735"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdist is executable">
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1734"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1733"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1732"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdither is executable">
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1731"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1730"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1729"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmflash is executable">
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1728"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1727"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1726"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmforge is executable">
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1725"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1724"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1723"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmhist is executable">
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1722"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1721"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1720"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmlabel is executable">
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1719"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1718"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1717"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmake is executable">
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1716"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1715"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1714"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmix is executable">
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1713"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1712"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1711"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmnorm is executable">
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1710"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1709"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1708"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmntsc is executable">
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1707"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1706"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1705"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmpat is executable">
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1704"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1703"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1702"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmquant is executable">
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1701"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1700"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1699"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmqvga is executable">
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1698"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1697"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1696"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmrelief is executable">
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1695"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1694"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1693"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmshift is executable">
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1692"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1691"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1690"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmspread is executable">
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1689"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1688"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1687"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoacad is executable">
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1686"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1685"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1684"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtobmp is executable">
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1683"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1682"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1681"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoeyuv is executable">
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1680"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1679"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1678"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtogif is executable">
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1677"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1676"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1675"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoicr is executable">
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1674"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1673"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1672"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoilbm is executable">
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1671"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1670"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1669"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtojpeg is executable">
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1668"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1667"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1666"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoleaf is executable">
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1665"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1664"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1663"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtolj is executable">
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1662"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1661"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1660"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtomitsu is executable">
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1659"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1658"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1657"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtompeg is executable">
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1656"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1655"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1654"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoneo is executable">
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1653"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1652"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1651"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopcx is executable">
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1650"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1649"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1648"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopgm is executable">
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1647"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1646"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1645"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopi1 is executable">
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1644"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1643"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1642"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:803" version="2" class="vulnerability">
      <metadata>
        <title>RedHat Code Execution and DoS Vulnerabilities in PWLib</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>PWLib</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097"/>
        <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Added a program_name element to rlt-217">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.185-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:40.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pwlib version is less than 1.4.7-4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2321"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="a program is listening on TCP or UDP port 1720" negate="false" test_ref="oval:org.mitre.oval:tst:2320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:802" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of wins.exe is less than 5.2.3790.99" negate="false" test_ref="oval:org.mitre.oval:tst:2322"/>
          <criterion comment="the patch kb830352 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:801" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT Terminal Server WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:58.681-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:51.910-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
            <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
            <criterion comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 4.0.1381.33554" test_ref="oval:org.mitre.oval:tst:2323"/>
          <criterion negate="true" comment="the patch kb830352 is installed (Hotfix key)" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="the wins service is enabled" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:800" version="3" class="vulnerability">
      <metadata>
        <title>Windows NT WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:01.622-05:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:58.249-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:51.506-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
            <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the version of wins.exe is less than 4.0.1381.7255" test_ref="oval:org.mitre.oval:tst:2324"/>
          <criterion negate="true" comment="the patch kb830352 is installed (Hotfix key)" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="the wins service is enabled" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:80" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE ToolTalk Database Symbolic Link Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0678"/>
        <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:28.768-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:40.359-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 107893-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2969"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:8" version="1">
      <metadata>
        <title>SMB Rename Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-4696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4696" source="CVE"/>
        <description>Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:51.510-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:02.463-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Srv.sys is less than 5.0.2195.7106" test_ref="oval:org.mitre.oval:tst:37"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Srv.sys is less than 5.1.2600.1885" test_ref="oval:org.mitre.oval:tst:39"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Srv.sys is less than 5.1.2600.2974" test_ref="oval:org.mitre.oval:tst:111"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:41"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:799" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of msasn1.dll is less than 5.2.3790.88" negate="false" test_ref="oval:org.mitre.oval:tst:2325"/>
        <criterion comment="the patch kb828028 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:798" version="3" class="vulnerability">
      <metadata>
        <title>Office 2002 Remote Code Execution via Malformed Routing Slip</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0009"/>
        <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on ste:2179 (referenced by tst:2327) changed to pattern match, per Rob Hollis.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.063-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1339" date="2007-04-23T12:05:00.247-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:26:29.358-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:11:08.488-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2327"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6775.0" negate="false" test_ref="oval:org.mitre.oval:tst:2326"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:797" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T10:28:00.000-04:00" comment="">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criteria operator="OR" comment="a vulnerable version of msasn1.dll exists">
          <criteria operator="AND" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.119">
            <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
            <criterion comment="the version of msasn1.dll is less than 5.1.2600.119" test_ref="oval:org.mitre.oval:tst:2329"/>
          </criteria>
          <criteria operator="AND" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1274">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of msasn1.dll is less than 5.1.2600.1274" test_ref="oval:org.mitre.oval:tst:2328"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="the patch kb828028 is installed" test_ref="oval:org.mitre.oval:tst:2468"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:796" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:57.806-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:51.235-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
        <criterion comment="the version of msasn1.dll is less than 5.0.2195.6824" test_ref="oval:org.mitre.oval:tst:2330"/>
        <criterion negate="true" comment="the patch kb828028 is installed" test_ref="oval:org.mitre.oval:tst:2468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:795" version="4" class="vulnerability">
      <metadata>
        <title>Windows Script Engine Heap Overflow (Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Script Engine for JScript v5.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-08-24T11:01:00.000-04:00" comment="Added patch information to definition">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:38.925-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:13.852-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of jscript.dll is less than 5.5.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2906"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the patch js56nen.exe (5.5.0.8513 version) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2902"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:794" version="4" class="vulnerability">
      <metadata>
        <title>Windows Script Engine Heap Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Script Engine for JScript v5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-08-24T11:02:00.000-04:00" comment="Added patch information to definition">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:53.836-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:14.535-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:27.797-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of jscript.dll is less than 5.1.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2907"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the patch js56nen.exe (5.1.0.8513 version) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2903"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:793" version="1" class="vulnerability">
      <metadata>
        <title>IE6:XP,SP2 Java Proxy COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2087"/>
        <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-26T09:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-04T08:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false" test_ref="oval:org.mitre.oval:tst:2331"/>
        <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
          <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
          </criteria>
          <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:792" version="2" class="vulnerability">
      <metadata>
        <title>IE6 Double Byte Character Parsing Memory Corruption (Win2K/WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1189"/>
        <description>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:15.998-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:59.745-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:791" version="1" class="vulnerability">
      <metadata>
        <title>IE6 COM Object Instantiation Memory Corruption (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1186"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7906" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:491: Removed HKEY_LOCAL_MACHINE\ from the key, as it's specified as the hive.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:36:00.756-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-22T00:37:48.866-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:59.465-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:790" version="3" class="vulnerability">
      <metadata>
        <title>IE6:Server 2003 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:22:29.387-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:59.154-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.373" test_ref="oval:org.mitre.oval:tst:2335"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" test_ref="oval:org.mitre.oval:tst:2334"/>
            </criteria>
            <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" test_ref="oval:org.mitre.oval:tst:2334"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion negate="true" comment="use machine settings rather than individual user settings" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:79" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 RWall Daemon Syslog Format String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>rpc.rwalld</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0573"/>
        <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:16:00.472-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:04.742-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:40.174-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.rwalld exists" negate="false" test_ref="oval:org.mitre.oval:tst:3032"/>
          <criterion comment="Patch 112846-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2970"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.rwalld" negate="false" test_ref="oval:org.mitre.oval:tst:3030"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.rwalld executable">
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3029"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3028"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3027"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:789" version="3" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE6,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:1340 - Set xsi:nil to true on the name entity as we are only concerned with the existance of the key itself.">
              <contributor organization="Centennial Software">Jason Spashett</contributor>
            </modified>
            <status_change date="2006-06-23T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:38.339-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:03.185-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:58.863-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" negate="false" test_ref="oval:org.mitre.oval:tst:2338"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" negate="false" test_ref="oval:org.mitre.oval:tst:2337"/>
          </criteria>
          <criterion comment="the patch kb890923 is installed (XP Win2K Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2336"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:787" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTML Parsing Vulnerability (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1185"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7865" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:20:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:29.108-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:58.563-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:786" version="1" class="vulnerability">
      <metadata>
        <title>Network Connection Manager Interruption of Service (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2307"/>
        <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="netman.dll is less than 5.2.3790.2516" negate="false" test_ref="oval:org.mitre.oval:tst:2340"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:785" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX usermod(1M) Local Unauthorized Access.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-05-07T12:00:00.048-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-07T12:01:40.074-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:52.817-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.466-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.680-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02102" date="2008-07-14T10:21:00.322-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:22:19.346-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.912-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
            <criterion comment="OS-Core.SYS2-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:7877"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_34764 is installed" test_ref="oval:org.mitre.oval:tst:8277"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
          <criterion negate="true" comment="Patch PHCO_33142 is installed" test_ref="oval:org.mitre.oval:tst:8598"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
          <criterion negate="true" comment="Patch PHCO_34763 is installed" test_ref="oval:org.mitre.oval:tst:8081"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:784" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Telnet Environment Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Services for UNIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1205"/>
        <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the patch KB896428 for Services for UNIX is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2351"/>
        <criteria operator="OR" comment="Services for UNIX is instaled and a vulnerable version of telnet.exe exists">
          <criteria operator="AND" comment="Services for UNIX version 2.2 and telnet.exe version less than 5.3000.2073.13">
            <criterion comment="the version of telnet.exe is less than 5.3000.2073.13" negate="false" test_ref="oval:org.mitre.oval:tst:2350"/>
            <criterion comment="the software Services for UNIX is installed and the version is 2.2" negate="false" test_ref="oval:org.mitre.oval:tst:2349"/>
          </criteria>
          <criteria operator="AND" comment="Services for UNIX version 3.0 and telnet.exe version less than 7.0.1701.44">
            <criterion comment="the software Services for UNIX is installed and the version is 3.0" negate="false" test_ref="oval:org.mitre.oval:tst:2348"/>
            <criterion comment="the version of telnet.exe is less than 7.0.1701.44" negate="false" test_ref="oval:org.mitre.oval:tst:2347"/>
          </criteria>
          <criteria operator="AND" comment="Services for UNIX version 3.5 and telnet.exe version less than 8.0.1969.33">
            <criterion comment="the software Services for UNIX is installed and the version is 3.5" negate="false" test_ref="oval:org.mitre.oval:tst:2346"/>
            <criterion comment="the version of telnet.exe is less than 8.0.1969.33" negate="false" test_ref="oval:org.mitre.oval:tst:2345"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:783" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Plug and Play Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1983"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.701-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.880-04:00">ACCEPTED</status_change>
            <modified comment="Corrected tst:3429. Removed reference to ste:3948. Deprecated ste:3948" date="2007-02-12T10:38:00.383-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:40:21.525-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:27.634-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4033"/>
        <criterion comment="any SP is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3429"/>
        <criterion comment="the version of umpnpmgr.dll is less than 5.2.3790.360" negate="false" test_ref="oval:org.mitre.oval:tst:3457"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:782" version="3" class="vulnerability">
      <metadata>
        <title>IE6 for Server 2003 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T04:52:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="updated description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:59.058-05:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:22:35.053-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:58.289-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.327" test_ref="oval:org.mitre.oval:tst:2501"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2440" test_ref="oval:org.mitre.oval:tst:2500"/>
            </criteria>
            <criteria operator="AND" comment="    a vulnerable version of mshtml.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2440" test_ref="oval:org.mitre.oval:tst:2500"/>
            </criteria>
          </criteria>
          <criterion negate="true" comment="the patch kb883939 is installed" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="PNG image rendering enabled in Internet Explorer" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:781" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 InstallVersion.compareTo() DoS and Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2265"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:780" version="2" class="vulnerability">
      <metadata>
        <title>Server 2003 Path MTU Discovery Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:01.450-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
            <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="the version of Tcpip.sys is less than 5.2.3790.336" test_ref="oval:org.mitre.oval:tst:2354"/>
          <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
          <criterion comment="the patch KB893066 is installed" test_ref="oval:org.mitre.oval:tst:2353"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="Enable Path MTU Discovery is Disabled" test_ref="oval:org.mitre.oval:tst:2352"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:78" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Directory Traversal Command Execution (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0333"/>
        <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-08-04T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" negate="false" test_ref="oval:org.mitre.oval:tst:2971"/>
        <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:779" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP Kernel Debugger-based Buffer Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the patch Q811493 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2885"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" negate="false" test_ref="oval:org.mitre.oval:tst:2355"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:778" version="2" class="vulnerability">
      <metadata>
        <title>LSASS Privilege Escalation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
        <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.0.2195.6987" negate="false" test_ref="oval:org.mitre.oval:tst:2357"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:777" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 CSRSS Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Client Server Runtime System (CSRSS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0551"/>
        <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:776" version="2" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:40.296-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:57.997-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3828.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2359"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:775" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft MDAC 2.8 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Data Access Compnents 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.717-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:27.176-04:00">INTERIM</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.882-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-13T12:01:21.491-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.8 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
        <criterion comment="the version of odbcbcp.dll is less than 2000.85.1025.0" negate="false" test_ref="oval:org.mitre.oval:tst:2362"/>
        <criterion comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" negate="false" test_ref="oval:org.mitre.oval:tst:2361"/>
        <criteria operator="OR" comment="the patch q832483 is not installed">
          <criteria operator="AND" comment="32-bit edition of windows and patch q832483 is not installed">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
          </criteria>
          <criteria operator="AND" comment="64-bit edition of windows and patch q832483 is not installed">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2360"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:774" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:52:00.000-04:00" comment="modified wft-94 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:07.285-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:57.688-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false" test_ref="oval:org.mitre.oval:tst:2579"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:773" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Mozilla top.focus() Cross-Site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2266"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7721" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:491: Removed HKEY_LOCAL_MACHINE\ from the key, as it's specified as the hive.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:36:00.756-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-22T00:37:49.862-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:57.431-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:772" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Usermod Local Unauthorized Access Vulnerability instead of usermod Recursive Ownership Error.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.650-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:42:53.692-04:00">INTERIM</status_change>
            <modified comment="Updated definition title. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:42:00.035-04:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-04-10T13:44:28.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7717" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:491: Removed HKEY_LOCAL_MACHINE\ from the key, as it's specified as the hive.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:36:00.756-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-22T00:37:49.102-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:57.156-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:770" version="3" class="vulnerability">
      <metadata>
        <title>IE6,SP1 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T09:24:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:58.160-05:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:05.785-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:56.830-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1505 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2365"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1506 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2364"/>
          </criteria>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:77" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 GetObject File Retrieval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false" test_ref="oval:org.mitre.oval:tst:3075"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:769" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 Color Management Module Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Color Management Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1219"/>
        <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-08-03T11:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows Server 2003 with Service Pack 1">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criterion comment="the version of mscms.dll is less than 5.2.3790.2476" negate="false" test_ref="oval:org.mitre.oval:tst:2366"/>
        <criterion comment="the patch KB901214 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2697"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:768" class="vulnerability" version="1">
      <metadata>
        <title>Excel Malformed Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0028"/>
        <description>Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability."  NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-01-10T02:08:37">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-01-11T10:00:00-04:00">DRAFT</status_change>
            <status_change date="2007-02-20T13:40:56.619-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:27.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8955" test_ref="oval:org.mitre.oval:tst:155"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6823.0" test_ref="oval:org.mitre.oval:tst:152"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8117.0" test_ref="oval:org.mitre.oval:tst:154"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8117.0" test_ref="oval:org.mitre.oval:tst:156"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:767" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.10.01, B.10.10)</title>
        <affected family="unix">
          <platform>HP-UX 10</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.325-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.10.20) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2373"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2372"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2371"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2370"/>
        </criteria>
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01 or 10.10">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01">
            <criteria operator="AND" comment="700 Series OS Release 10.01">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:2369"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.01">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:2369"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.10">
            <criteria operator="AND" comment="700 Series OS Release 10.10">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:2368"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.10">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:2368"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_23947 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2367"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:766" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.246-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.446-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02072" date="2008-07-14T10:21:00.631-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:24:15.648-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_33791 is installed" test_ref="oval:org.mitre.oval:tst:8349"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_33790 is installed" test_ref="oval:org.mitre.oval:tst:8118"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8005"/>
          <criterion negate="true" comment="Patch PHNE_33792 is installed" test_ref="oval:org.mitre.oval:tst:8139"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:765" version="2" class="vulnerability">
      <metadata>
        <title>GNU GZip CHMod File Permission Modification Race ConditionWeakness</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0988"/>
        <description>Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.441-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.590-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:47:00.641-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:48:04.662-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:27.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4005"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4070"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116340-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3666"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116341-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3778"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120719-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3295"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120720-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:763" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2002 Remote Code Execution via Malformed Record</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031"/>
        <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2377) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:1360 (referenced by tst:2378) fixed: was pattern match, now equals.  Thanks to John Hoyland of Centenial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:53.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2378"/>
        <criterion comment="the version of excel.exe is less than 10.0.6789.0" negate="false" test_ref="oval:org.mitre.oval:tst:2377"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:762" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 5)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft SharePoint Team Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:53:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.964-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows 2000, XP, or 2003 is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          </criteria>
          <criterion comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" negate="false" test_ref="oval:org.mitre.oval:tst:2490"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SharePoint Team Services are enabled (2K, XP, 2003)" negate="false" test_ref="oval:org.mitre.oval:tst:2379"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7611" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T02:09:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:37.703-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:26.101-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:56.374-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.853-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:53:30.999-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:21.209-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:761" class="vulnerability" version="1">
      <metadata>
        <title>Script Error Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5579" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5579"/>
        <description>Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka "Script Error Handling Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:01.277-05:00">INTERIM</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:56.052-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" negate="false" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" negate="false" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3020" negate="false" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" negate="false" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:760" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Byte-range DoS Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:76" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Process Handle Duplication Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0367"/>
        <description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" negate="false" test_ref="oval:org.mitre.oval:tst:2973"/>
        <criterion comment="Patch Q320206 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2972"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:759" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla Framed Site Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1937" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1937"/>
        <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:755" version="2" class="vulnerability">
      <metadata>
        <title>Sun Java System Access Manager Local Authentication Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <platform>Sun Solaris 9</platform>
          <product>Access Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0531"/>
        <description>Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.102-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.406-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:52:00.016-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:53:06.046-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:26.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="x86" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        <criterion comment="Sun Java System Access Manager 7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3551"/>
        <criterion comment="Patch 120955-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3363"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:753" class="vulnerability" version="1">
      <metadata>
        <title>Excel Malformed Palette Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0031"/>
        <description>Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-01-10T02:08:37">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-01-11T10:00:00-04:00">DRAFT</status_change>
            <status_change date="2007-02-20T13:40:55.803-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:26.707-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8955" test_ref="oval:org.mitre.oval:tst:155"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6823.0" test_ref="oval:org.mitre.oval:tst:152"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8117.0" test_ref="oval:org.mitre.oval:tst:154"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:752" version="1">
      <metadata>
        <title>Microsoft Excel Malformed LABEL record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-1309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1309" source="CVE"/>
        <description>Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:37.395-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:49.031-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:751" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft MDAC 2.7 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Data Access Compnents 2.7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.717-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:27.527-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:20.986-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="MDAC 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists">
          <criteria operator="AND" comment="MDAC 2.7 (RTM) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9002.0">
            <criterion comment="MDAC 2.7 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2590"/>
            <criterion comment="the version of sqlsrv32.dll is less than 2000.81.9002.0" negate="false" test_ref="oval:org.mitre.oval:tst:2384"/>
            <criterion comment="the version of odbcbcp.dll is less than 2000.81.9002.0" negate="false" test_ref="oval:org.mitre.oval:tst:2383"/>
          </criteria>
          <criteria operator="AND" comment="MDAC 2.7 (SP1) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9042.0">
            <criterion comment="MDAC 2.7 (SP1) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2382"/>
            <criterion comment="the version of sqlsrv32.dll is less than 2000.81.9042.0" negate="false" test_ref="oval:org.mitre.oval:tst:2381"/>
            <criterion comment="the version of odbcbcp.dll is less than 2000.81.9042.0" negate="false" test_ref="oval:org.mitre.oval:tst:2380"/>
          </criteria>
        </criteria>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:75" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.12 Vulnerability in DCERPC Dissector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0428" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0428"/>
        <description>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.279-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7496" version="2" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP2 for Server 2003 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:40:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:267. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:19:00.959-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:19:46.066-05:00">INTERIM</status_change>
            <modified comment="Fixed obj:246: Removed HKEY_LOCAL_MACHINE\ from the key, as it's specified as the hive.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:36:00.713-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:55.564-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 2 for XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:269"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than  6.0.2900.2523" negate="false" test_ref="oval:org.mitre.oval:tst:268"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than  6.0.2900.2524" negate="false" test_ref="oval:org.mitre.oval:tst:267"/>
          </criteria>
          <criterion comment="the patch kb834707  is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:266"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:749" version="1" class="vulnerability">
      <metadata>
        <title>bzip2 Decompression Bomb</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>bzip2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1260"/>
        <description>bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" negate="false" test_ref="oval:org.mitre.oval:tst:2386"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/bzip2 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2385"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:748" version="1" class="patch">
      <metadata>
        <title>patch IE7-KB928090-WindowsServer2003-x64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB928090-WindowsServer2003-x64-enu.exe"/>
        <description>The patch IE7-KB928090-WindowsServer2003-x64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-016 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:26.559-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:28.424-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:720" comment="Microsoft Windows XP Professional x64 Edition SP1 is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criteria operator="OR">
          <criterion test_ref="oval:org.mitre.oval:tst:3721" comment="the version of Iexplore.exe is less than 7.0.6000.16414"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3876" comment="the version of Mshtml.dll is less than 7.0.6000.16414"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:747" version="1">
      <metadata>
        <title>Winsock Hostname Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3440" source="CVE"/>
        <description>Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:37.143-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:48.747-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dnsapi.dll is less than 5.0.2195.7100" test_ref="oval:org.mitre.oval:tst:130"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of dnsapi.dll is less than 5.1.2600.1863" test_ref="oval:org.mitre.oval:tst:81"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of dnsapi.dll is less than 5.1.2600.2938" test_ref="oval:org.mitre.oval:tst:198"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.2745" test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.558" test_ref="oval:org.mitre.oval:tst:159"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.2745" test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:746" class="vulnerability" version="1">
      <metadata>
        <title>Word Malformed Data Structures Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6456"/>
        <description>Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:26.417-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:28.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition definition_ref="oval:org.mitre.oval:def:238" comment="Word Malformed String Vulnerability"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:745" version="2" class="vulnerability">
      <metadata>
        <title>IE v6.0 (XP) Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:51:00.000-04:00" comment="modified wft-93 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2737.800" negate="false" test_ref="oval:org.mitre.oval:tst:2580"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7448" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:31:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-14T11:27:00.000-04:00" comment="Fixed CVE reference; was CVE-2003-0727 because of a typo.  Now correctly refers to CVE-2004-0727.  Change was implemented by Matthew Wojcik.">
              <contributor organization="MessageLabs">Andrew Simmons</contributor>
            </modified>
            <status_change date="2005-12-16T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added platforms based on MS Bulletin information." date="2008-06-27T09:26:00.268-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-06-27T09:44:31.282-04:00">INTERIM</status_change>
            <status_change date="2008-07-14T04:00:23.150-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:744" version="1" class="vulnerability">
      <metadata>
        <title>Gaim DoS via Yahoo! Message</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1269"/>
        <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="gaim RPM earlier than 1:1.3.1-0.el3" negate="false" test_ref="oval:org.mitre.oval:tst:2740"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/gaim is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:2739"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:743" version="3" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 5)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-03-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2003-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:50:00.000-04:00" comment="modified wft-114 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:22:00.000-04:00" comment="modified wft-31 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:14.792-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:26.161-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists">
            <criterion comment="the version of fp4areg.dll is less than 4.0.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2681"/>
            <criterion comment="the version of fp30reg.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2680"/>
          </criteria>
          <criterion comment="the patch q810217 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2707"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2706"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:742" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Improper Handling of Synthetic Events in Mozilla</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2260"/>
        <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:740" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Office Smart Tag Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-3868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3868" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:50.786-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:01.634-05:00">ACCEPTED</status_change>
            <modified date="2007-12-29T04:31:34" comment="Added application criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-01-01T09:14:17.637-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:19:32.709-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="A vulnerable application is installed">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
        </criteria>
        <criteria operator="OR">
          <criteria operator="AND" comment="Office 2002">
            <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
            <criterion comment="The version of mso.dll is less than 10.0.6817.0." test_ref="oval:org.mitre.oval:tst:158"/>
          </criteria>
          <criteria operator="AND" comment="Office 2003">
            <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
            <criterion comment="The version of mso.dll is less than 11.0.8107.0." test_ref="oval:org.mitre.oval:tst:98"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:74" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE dtspcd Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>dtspcd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0803"/>
        <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:14:00.836-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:14:25.949-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File dtspcd exists" negate="false" test_ref="oval:org.mitre.oval:tst:2983"/>
          <criterion comment="Patch 106934-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2974"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains dtspcd" negate="false" test_ref="oval:org.mitre.oval:tst:2981"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File dtspcd executable">
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2980"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2979"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2978"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:738" version="2">
      <metadata>
        <title>Redirect Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3280" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3280" source="CVE"/>
        <description>Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, aka "Redirect Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:36.755-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:48.367-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:18.371-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:55.268-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:736" version="2" class="vulnerability">
      <metadata>
        <title>MIT Kerberos 5 Key Distribution Center Remote Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Kerberos</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1175"/>
        <description>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.863-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.079-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:02:00.285-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:04:28.310-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112536-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112537-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3424"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112237-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3567"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112238-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3898"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112390-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3640"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112240-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3497"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112908-20 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3389"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 115168-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3624"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120469-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3561"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120470-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:735" version="1" class="vulnerability">
      <metadata>
        <title>Apache Integer Overflow in pcre_compile.c</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:733" version="2" class="vulnerability">
      <metadata>
        <title>IE v6.0 (XP) HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-01-21T05:00:00.000-04:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2663"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:73" version="2" class="vulnerability">
      <metadata>
        <title>Integer Overflow Vulnerabilities in Ethereal 0.9.11</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0357"/>
        <description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.945-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:729" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla DOM Node Spoofing</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2269"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:728" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX 11 Perl rmtree Race Condition</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0448"/>
        <description>Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.495-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.663-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:48:00.580-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:49:04.605-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Perl 5.6 or 5.8 vulnerable on 11.00, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Perl version 5.6.0 is installed or 5.8.0 without revision G or later is installed" negate="false">
            <criterion comment="Perl 5.6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3419"/>
            <criterion comment="Perl 5.8.0 (revision F or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.00 or 11.11" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision C or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3226"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision E or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3635"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.3 vulnerable on 11.0, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.3,revision A is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3847"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:727" version="1" class="vulnerability">
      <metadata>
        <title>Korean IME Privilege Elevation Vulnerability in Office 2003 and Accessories</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0008"/>
        <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of Imekr70.ime is less than 7.0.8002.0 (Office 2003 and Accessories)" negate="false" test_ref="oval:org.mitre.oval:tst:2389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:726" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.00 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.288-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.492-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:52:00.826-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:53:23.849-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.287-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.157-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.290-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33395 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:724" version="2" class="vulnerability">
      <metadata>
        <title>MIT Kerberos 5 KRB5_AName_To_Localname Multiple Principal Name Buffer Overrun Vulnerabilities</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 7</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523"/>
        <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.045-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.217-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:49:00.749-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:50:17.774-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.042-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112536-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3544"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 112537-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3498"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112237-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3354"/>
            <criterion comment="Patch 112390-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3509"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 112240-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3366"/>
            <criterion comment="Patch 112238-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4043"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112908-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3824"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 115168-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4066"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Target's configuration meets 101512 configuration criteria." negate="false">
            <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)" negate="false">
              <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3514"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3192"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3873"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3369"/>
            </criteria>
            <criteria operator="AND" comment="SEAM is not installed, but target is a kerberos client." negate="false">
              <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)" negate="true">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3514"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3192"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3873"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3369"/>
              </criteria>
              <criterion comment="/etc/krb5/krb5.conf is configured as a kerberos client" negate="false" test_ref="oval:org.mitre.oval:tst:3487"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:723" version="1">
      <metadata>
        <title>DNS Client Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3441" source="CVE"/>
        <description>Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response.  NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:36.303-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:47.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dnsapi.dll is less than 5.0.2195.7100" test_ref="oval:org.mitre.oval:tst:130"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of dnsapi.dll is less than 5.1.2600.1863" test_ref="oval:org.mitre.oval:tst:81"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of dnsapi.dll is less than 5.1.2600.2938" test_ref="oval:org.mitre.oval:tst:198"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.2745" test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.558" test_ref="oval:org.mitre.oval:tst:159"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.2745" test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:722" version="2" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:57.849-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:54.977-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:721" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Web Client Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Web Client Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1207"/>
        <description>Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of webclnt.dll is less than 5.2.3790.316" test_ref="oval:org.mitre.oval:tst:2392"/>
        <criterion negate="true" comment="the patch kb896426 is installed (Hotfix key)" test_ref="oval:org.mitre.oval:tst:2391"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:72" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT Variant of Chunked Encoding Buffer Overrun</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0147"/>
        <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.430-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:12.556-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:51.497-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7194" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T07:44:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:58.632-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:54.717-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:719" version="2">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3638" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3638" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:35.956-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:47.310-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:14.996-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:54.389-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:718" version="1" class="patch">
      <metadata>
        <title>patch IE7-KB928090-WindowsServer2003-x64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB928090-WindowsServer2003-x64-enu.exe"/>
        <description>The patch IE7-KB928090-WindowsServer2003-x64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-016 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.794-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:27.752-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:730" comment="Microsoft Windows Server 2003 (x64) is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criteria operator="OR">
          <criterion test_ref="oval:org.mitre.oval:tst:3721" comment="the version of Iexplore.exe is less than 7.0.6000.16414"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3876" comment="the version of Mshtml.dll is less than 7.0.6000.16414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:717" version="2" class="vulnerability">
      <metadata>
        <title>gftp Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gftp</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0372"/>
        <description>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-25T10:22:00.000-04:00" comment="modified upt-62 - Changed DATA operation to OR (to test for any exec bit set, not all).  Fixed typo in comment.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-01-25T07:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="gftp rpm is earlier than 1:2.0.14-4" negate="false" test_ref="oval:org.mitre.oval:tst:2394"/>
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="gftp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:716" version="1" class="vulnerability">
      <metadata>
        <title>WebClient Service Unchecked Buffer Remote Code Execution (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0013"/>
        <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of webclnt.dll is less than 5.2.3790.2591 (64-bit,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:2395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:714" version="2" class="vulnerability">
      <metadata>
        <title>Win2k Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:11.052-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:24.629-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.0.2195.7071 or T2embed.dll &lt;5.0.2195.7073 (Win2k,SP4)">
          <criterion comment="the version of Fontsub.dll is less than 5.0.2195.7071" negate="false" test_ref="oval:org.mitre.oval:tst:2397"/>
          <criterion comment="the version of T2embed.dll is less than 5.0.2195.7073" negate="false" test_ref="oval:org.mitre.oval:tst:2396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:713" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Hyperlink Object Library Unchecked Buffer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Hyperlink Object Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0057"/>
        <description>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-11T09:34:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of hlink.dll is less than 5.2.3790.227" negate="false" test_ref="oval:org.mitre.oval:tst:2399"/>
        <criterion comment="the patch kb888113 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2398"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:712" version="4" class="vulnerability">
      <metadata>
        <title>Animated Cursor Denial of Service (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Animated Cursor</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1305"/>
        <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:00.954-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.059-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:28.434-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:20.742-05:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:57.209-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:50.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of user32.dll is less than 4.0.1381.7342" test_ref="oval:org.mitre.oval:tst:2400"/>
        <criterion negate="true" comment="the patch kb891711 is installed" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:711" version="1" class="vulnerability">
      <metadata>
        <title>ImageMagick Buffer Overflow in ReadPNMImage()</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1275" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1275"/>
        <description>Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-28T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ImageMagick RPM earlier than 0:5.5.6-14" negate="false" test_ref="oval:org.mitre.oval:tst:2401"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:710" version="2" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-159 - unchecked value">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:41:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false" test_ref="oval:org.mitre.oval:tst:2402"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:71" version="2" class="vulnerability">
      <metadata>
        <title>Privilege Escalation Using Cached Admin Connection</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0344"/>
        <description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-06-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-07T12:00:00.000-04:00" comment="modified wft-222 - corrected literal component of file path. It was missing the leading '\'">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified date="2005-04-07T09:25:00.000-04:00" comment="modified wft-222 - Corrected comment">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
          <criterion comment="the version of sqlservr.exe is less than 2000.80.296.0" negate="false" test_ref="oval:org.mitre.oval:tst:2976"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Mixed Mode Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7095" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T05:31:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
        <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
          <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
          </criteria>
          <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:709" class="vulnerability" version="1">
      <metadata>
        <title>Flash Improper Memory Access Arbitrary Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3587"/>
        <description>Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:00.827-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:54.111-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="WinXP,SP2 or WinXP,SP1 (64-bit)" operator="OR">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
        </criteria>
        <criteria comment="Flash.ocx exists without upgrades to Flash8 or Flash9" operator="AND">
          <criterion comment="Flash.ocx exists" test_ref="oval:org.mitre.oval:tst:79"/>
          <criterion comment="Flash8.ocx  (minimum version 8.0.22.0) is not installed" test_ref="oval:org.mitre.oval:tst:83" negate="true"/>
          <criterion comment="Flash9.ocx  (minimum version 9.0.16.0) is not installed" test_ref="oval:org.mitre.oval:tst:85" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7084" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:22:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:28.926-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:53.871-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:708" version="1" class="vulnerability">
      <metadata>
        <title>.lnk File-Open Remote Code Execution Vulnerability (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="shell32.dll is less than 6.0.3790.2521" negate="false" test_ref="oval:org.mitre.oval:tst:2404"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:704" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:00.642-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.0.2195.6870" negate="false" test_ref="oval:org.mitre.oval:tst:2407"/>
          <criterion comment="the patch kb830352 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:702" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Privilege Escalation/DoS Vulnerability (6293270)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0190"/>
        <description>Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-12T11:25:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102066 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Contributing factors for Solaris 9, Sun Alert ID 102066 criteria.">
            <criterion comment="Patch 112234-11 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2413"/>
            <criterion comment="Patch 112234-12 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2412"/>
            <criterion comment="Patch 117172-16 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:2411"/>
          </criteria>
          <criterion comment="Patch 118559-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2410"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118844-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2409"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:701" version="1" class="vulnerability">
      <metadata>
        <title>WMF Rendering Code Execution Vulnerability (64-bit Windows XP and Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2123"/>
        <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="64-bit XP or Server 2003 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.2542" negate="false" test_ref="oval:org.mitre.oval:tst:2414"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:700" class="vulnerability" version="1">
      <metadata>
        <title>Word Macro Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0208"/>
        <description>Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.484-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:27.434-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Word 2000" operator="AND">
          <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
          <criterion comment="the version of winword.exe is less than 9.0.0.8958" test_ref="oval:org.mitre.oval:tst:3510"/>
        </criteria>
        <criteria comment="Word 2002" operator="AND">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of winword.exe is less than 10.0.6826.0" test_ref="oval:org.mitre.oval:tst:3265"/>
        </criteria>
        <criteria comment="Word 2003" operator="AND">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of winword.exe is less than 11.0.8125.0" test_ref="oval:org.mitre.oval:tst:3593"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:70" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE dtspcd Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>dtspcd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0803"/>
        <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:14:00.836-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:14:26.106-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File dtspcd exists" negate="false" test_ref="oval:org.mitre.oval:tst:2983"/>
          <criterion comment="Patch 108949-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2982"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains dtspcd" negate="false" test_ref="oval:org.mitre.oval:tst:2981"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File dtspcd executable">
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2980"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2979"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2978"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 kcms_configure Command-Line Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>kcms_configure</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0594"/>
        <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File kcms_configure exists" negate="false" test_ref="oval:org.mitre.oval:tst:3144"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File kcms_configure executable and SUID or SGID">
            <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3143"/>
            <criteria operator="OR" comment="File kcms_configure executable and SUID or SGID">
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3142"/>
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:699" version="3" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 4)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-03-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2003-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:50:00.000-04:00" comment="modified wft-114 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:22:00.000-04:00" comment="modified wft-31 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:56.519-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:50.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists">
            <criterion comment="the version of fp4areg.dll is less than 4.0.02.7523" test_ref="oval:org.mitre.oval:tst:2681"/>
            <criterion comment="the version of fp30reg.dll is less than 4.00.02.7523" test_ref="oval:org.mitre.oval:tst:2680"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (WinNT)" test_ref="oval:org.mitre.oval:tst:2526"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:698" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.2777 or T2embed.dll &lt;5.1.2600.2777 (WinXP,SP2)">
          <criterion comment="the version of Fontsub.dll is less than 5.1.2600.2777" negate="false" test_ref="oval:org.mitre.oval:tst:2416"/>
          <criterion comment="the version of T2embed.dll is less than 5.1.2600.2777" negate="false" test_ref="oval:org.mitre.oval:tst:2415"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:697" version="3" class="vulnerability">
      <metadata>
        <title>IE6,SP1 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:07.513-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:53.538-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2418"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2417"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:695" version="3" class="vulnerability">
      <metadata>
        <title>MS Excel 2002 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-16 - wft-16 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2419) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1377 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:51.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2420"/>
        <criterion comment="the version of excel.exe is less than 10.0.5815.0" negate="false" test_ref="oval:org.mitre.oval:tst:2419"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:694" version="2">
      <metadata>
        <title>Visual Basic for Applications Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Visual Basic</product>
        </affected>
        <reference ref_id="CVE-2006-3649" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3649" source="CVE"/>
        <description>Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:35.094-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.846-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.744-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:25:45.747-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:26.766-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Vbe6.dll is installed and has a version less than 6.4.99.72" test_ref="oval:org.mitre.oval:tst:94"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:690" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Temporary Internet Files folders Name Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1188"/>
        <description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:69" version="2" class="vulnerability">
      <metadata>
        <title>Off-by-one Vulnerabilities in Ethereal 0.9.11</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0356"/>
        <description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.572-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:689" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false" test_ref="oval:org.mitre.oval:tst:2581"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:688" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.23 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.358-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.763-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:53:00.978-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:53:50.998-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:24.308-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.069-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_32606 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:687" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:49:00.000-04:00" comment="modified wft-91 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:42.977-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:53.220-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false" test_ref="oval:org.mitre.oval:tst:2582"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:686" version="1" class="vulnerability">
      <metadata>
        <title>TIP Request Validation Process Permits Denial of Service (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2539"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:685" version="1" class="vulnerability" deprecated="true">
      <metadata>
        <title>Suppressed: Duplicate of OVAL1959</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-02-09T12:00:00.000-04:00" comment="modified cmp-35 - Corrected test comment">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wrt-35 - wrt-35 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2007-03-01T12:01:01" comment="Deprecated in favor of oval:org.mitre.oval:def:1959.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-01T12:01:01">DEPRECATED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.928-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criterion comment="the version of mswrd6.wpc is less than 10.0.803.2" negate="false" test_ref="oval:org.mitre.oval:tst:2422"/>
          <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Word for Windows 6.0 Converter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2421"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:684" version="2" class="patch">
      <metadata>
        <title>patch IE7-KB929969-WindowsXP-x86-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB929969-WindowsXP-x86-enu.exe"/>
        <description>The patch IE7-KB929969-WindowsXP-x86-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-004 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.132-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:27.264-04:00">ACCEPTED</status_change>
            <modified comment="Changed object reference to refer to the registry instead of a hard-coded path" date="2008-04-14T13:12:00.428-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T13:14:45.283-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:26.337-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:754" comment="Microsoft Windows XP (x86) SP2 is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3946" comment="the version of Vgx.dll is less than 7.0.6000.16386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:683" version="1" class="vulnerability">
      <metadata>
        <title>WebClient Service Unchecked Buffer Remote Code Execution (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0013"/>
        <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of webclnt.dll is less than 5.1.2600.1790 (XP,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:2423"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6829" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:37:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:01.100-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:52.941-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:682" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Agent Security Prompt Spoofing Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Agent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1214"/>
        <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T07:25:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added cve description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-17T09:54:00.000-04:00" comment="Updated obj:1000 to use new variable var:759 for path reference rather than var:200.  Now uses 'msagent' subdir of SystemRoot instead of System32.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-11-17T09:54:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:00.438-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3423" negate="false" test_ref="oval:org.mitre.oval:tst:2425"/>
          <criterion comment="the patch kb890046 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2424"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:681" version="3" class="vulnerability">
      <metadata>
        <title>Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>NetDDE Agent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1230"/>
        <description>NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T03:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.274-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:37.477-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:20.474-05:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:55.818-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:50.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
        <criterion negate="true" comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of user32.dll is less than 4.0.1381.7177" test_ref="oval:org.mitre.oval:tst:2430"/>
        <criterion comment="the version of gdi32.dll is less than 4.0.1381.7177" test_ref="oval:org.mitre.oval:tst:2429"/>
        <criterion comment="the version of winsrv.dll is less than 4.0.1381.7202" test_ref="oval:org.mitre.oval:tst:2428"/>
        <criterion comment="the version of win32k.sys is less than 4.0.1381.7207" test_ref="oval:org.mitre.oval:tst:2427"/>
        <criterion negate="true" comment="Patch Q328310 Installed" test_ref="oval:org.mitre.oval:tst:2426"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:68" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 7 admintool Local Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0089"/>
        <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:25:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.775-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1726, which had been badly mangled during conversion from OVAL 4.2 to 5.0.  Operation set to pattern match on path, and terminal regexp anchor moved from filename to path." date="2007-01-22T16:24:00.728-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:26:00.857-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:52.685-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
          <criterion comment="Patch 108721-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2986"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:679" version="2" class="patch">
      <metadata>
        <title>IE7-KB929969-WindowsServer2003-ia64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB929969-WindowsServer2003-ia64-enu.exe"/>
        <description>The patch IE7-KB929969-WindowsServer2003-ia64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-004 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:23.989-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:27.086-04:00">ACCEPTED</status_change>
            <modified comment="Changed object reference to refer to the registry instead of a hard-coded path" date="2008-04-14T13:12:00.428-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T13:14:44.874-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:26.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition definition_ref="oval:org.mitre.oval:def:396" comment="Microsoft Windows Server 2003 (ia64) Gold is installed"/>
          <extend_definition definition_ref="oval:org.mitre.oval:def:1205" comment="Microsoft Windows Server 2003 (ia64) SP1 is installed"/>
        </criteria>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3946" comment="the version of Vgx.dll is less than 7.0.6000.16386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6788" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 (64-Bit) Unchecked Buffer in NetDDE</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T04:23:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.630-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:52:11.035-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:20.258-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criteria operator="OR" comment="a vulnerable version of netdde.exe exists">
          <criterion comment="the version of netdde.exe is less than 5.2.3790.184" negate="false" test_ref="oval:org.mitre.oval:tst:315"/>
          <criterion comment="the 64-bit WOW version of netdde.exe is less than 5.2.3790.193" negate="false" test_ref="oval:org.mitre.oval:tst:271"/>
        </criteria>
        <criteria operator="OR" comment="a vulnerable version of nddenb32.dll exists">
          <criterion comment="the version of nddenb32.dll is less than 5.2.3790.173" negate="false" test_ref="oval:org.mitre.oval:tst:316"/>
          <criterion comment="the 64-bit WOW version of nddenb32.dll is less than 5.2.3790.193" negate="false" test_ref="oval:org.mitre.oval:tst:270"/>
        </criteria>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:678" version="1" class="vulnerability">
      <metadata>
        <title>TCP/IP IGMP v3 Denial of Service (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0021"/>
        <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.2617 (64-bit,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:2431"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:677" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla XML Parser Read Beyond Buffer Bug</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0298" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0298"/>
        <description>The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:29:53.020-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2287" date="2007-03-06T07:58:00.046-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2288" date="2007-03-06T07:58:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:23.760-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:17.870-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:11:08.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:676" version="1" class="vulnerability">
      <metadata>
        <title>PostgreSQL Character Conversion Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>postgresql</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1409"/>
        <description>PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-27T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="rh-postgresql-server is earlier than 0:7.3.10-1" negate="false" test_ref="oval:org.mitre.oval:tst:2433"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="postmaster (the PostgreSQL master daemon) is running" negate="false" test_ref="oval:org.mitre.oval:tst:2432"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:675" version="1" class="vulnerability">
      <metadata>
        <title>MS Excel 97 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 97</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-14 - wft-14 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2434) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 97 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2435"/>
        <criterion comment="the version of excel.exe is less than 8.00.01.9904" negate="false" test_ref="oval:org.mitre.oval:tst:2434"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:673" version="1">
      <metadata>
        <title>Windows 2000 Kernel Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3444" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3444" source="CVE"/>
        <description>Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:34.552-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7098" test_ref="oval:org.mitre.oval:tst:46"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:671" version="2" class="vulnerability">
      <metadata>
        <title>EMF Rendering Denial of Service Vulnerability (64-bit Windows XP and Server 2003,Unpatched)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0803"/>
        <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed unneeded ste:2282 from tst:2437. Deprecated ste:2282 since it is no longer used." date="2007-01-12T07:06:00.595-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-12T07:08:59.602-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:52.335-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="64-bit XP or Server 2003 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.419" negate="false" test_ref="oval:org.mitre.oval:tst:2436"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:670" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla JavaScript Garbage-Collection Hazards in jsinterp.c</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0292"/>
        <description>The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to ste:2286 and deprectated ste:2286" date="2007-02-12T10:30:00.540-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:32:01.116-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2287" date="2007-03-06T07:58:00.046-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2288" date="2007-03-06T07:58:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2285" date="2007-03-06T08:03:00.800-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2290" date="2007-03-06T08:04:00.435-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2293" date="2007-03-06T08:07:00.205-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:23.477-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:21.365-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1386" date="2007-04-23T12:05:00.444-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1388" date="2007-04-23T12:05:00.504-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1389" date="2007-04-23T12:05:00.056-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Corrected definition to check for Mozilla suite 1.7.12. Implemented by Jon Baker of the MITRE Corporation." date="2007-05-07T08:38:00.156-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:50.528-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird pre-1.5 is installed without an upgraded Firefox (1.5.0.1)">
          <criterion comment="Mozilla Thunderbird pre-1.5" negate="false" test_ref="oval:org.mitre.oval:tst:2448"/>
          <criterion comment="Thunderbird pre-1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2447"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox pre-1.5 is installed">
          <criterion comment="Mozilla Firefox pre-1.5" negate="false" test_ref="oval:org.mitre.oval:tst:2445"/>
          <criterion comment="Firefox pre-1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2444"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:67" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8 admintool Local Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0089"/>
        <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:24:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.346-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1726, which had been badly mangled during conversion from OVAL 4.2 to 5.0.  Operation set to pattern match on path, and terminal regexp anchor moved from filename to path." date="2007-01-22T16:24:00.728-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:26:01.442-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:52.089-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
          <criterion comment="Patch 110453-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2987"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:669" class="vulnerability" version="1">
      <metadata>
        <title>Windows Media Format ASX Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6134"/>
        <description>Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:00.223-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:51.855-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:102" comment="Wmvcore.dll for Windows Media Format 7.1 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:174" comment="the version of Wmvcore.dll is less than 7.10.0.3079"/>
        </criteria>
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:125" comment="Wmvcore.dll for Windows Media Format 9.0 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:112" comment="the version of Wmvcore.dll is less than 9.0.0.3265"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition definition_ref="oval:org.mitre.oval:def:521" comment="Windows XP, SP2 is installed"/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:191" comment="the version of Wmvcore.dll is less than 10.0.0.3702"/>
        </criteria>
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:2747" comment="a 64-bit version of Windows is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:117" comment="the version of Wmvcore.dll is less than 10.0.0.3810"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
          <criterion test_ref="oval:org.mitre.oval:tst:2747" negate="true" comment="a 64-bit version of Windows is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:116" comment="the version of Wmvcore.dll is less than 10.0.0.3708"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:668" version="3" class="vulnerability">
      <metadata>
        <title>MS Word 2002 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2003-11-19T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-22 by correcting literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.0.5815.0" negate="false" test_ref="oval:org.mitre.oval:tst:2449"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:667" version="2" class="vulnerability">
      <metadata>
        <title>ypserv NIS Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>ypserv</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0251" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0251"/>
        <description>ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.920-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.014-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ypserv version is less than 2.8-0.9E" negate="false" test_ref="oval:org.mitre.oval:tst:2451"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ypserv is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:664" version="2" class="vulnerability">
      <metadata>
        <title>Code Execution Vulnerability in XPDF PDF Viewer</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>xpdf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0434" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0434"/>
        <description>Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.685-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.816-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="xpdf version is less than 2.0.1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2455"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="xpdf is executable">
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2454"/>
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2453"/>
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:662" version="2" class="vulnerability">
      <metadata>
        <title>lpsched Local System Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0227"/>
        <description>Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-16T12:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1394 to more correctly look for subdirectories under /etc/lp/printers." date="2007-01-22T16:00:00.391-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:01:01.488-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:51.556-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109320-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2464"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109321-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2462"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113329-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2461"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 114980-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2460"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (sparc) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 120467-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2458"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 120468-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2457"/>
        </criteria>
        <criterion comment="Target is configured as a print server" negate="false" test_ref="oval:org.mitre.oval:tst:2456"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6600" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:23:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:43.980-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:51.304-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:66" version="1" class="vulnerability">
      <metadata>
        <title>IIS ASP Function Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0223" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0223"/>
        <description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" negate="false" test_ref="oval:org.mitre.oval:tst:2988"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6579" version="3" class="vulnerability">
      <metadata>
        <title>Windows (ME, NT, 2K, XP), IE v6,SP1 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:56:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:07.043-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:50.989-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:657" version="2" class="vulnerability">
      <metadata>
        <title>xinitd Memory Leak Invites Denial of Service Attack</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>xinetd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0211"/>
        <description>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-17T12:00:00.000-04:00" comment="Changed tested epoch in xinetd test rvt-253 to 2, based on testing.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.150-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="xinetd version is less than 2:2.3.11-1.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2467"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="xinetd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2466"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:653" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of msasn1.dll is less than 5.0.2195.6823" negate="false" test_ref="oval:org.mitre.oval:tst:2469"/>
        <criterion comment="the patch kb828028 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:651" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 or 11.23 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.103-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.450-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:43:00.954-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:44:10.985-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:23.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:65" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 kcms_configure Command-Line Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>kcms_configure</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0594"/>
        <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File kcms_configure exists" negate="false" test_ref="oval:org.mitre.oval:tst:3144"/>
          <criterion comment="Patch 107337-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2989"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File kcms_configure executable and SUID or SGID">
            <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3143"/>
            <criteria operator="OR" comment="File kcms_configure executable and SUID or SGID">
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3142"/>
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:648" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:50.907-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.972-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.030-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2472"/>
        <criteria operator="OR" comment="Either PHNE_30983 or PHNE_31732 is installed" negate="true">
          <criterion comment="Patch PHNE_30983 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2471"/>
          <criterion comment="Patch PHNE_31732 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:647" version="1" class="vulnerability">
      <metadata>
        <title>mikmod Long Filename Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mikmod</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0427"/>
        <description>Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="mikmod RPM prior to 0:3.1.6-22.EL3" negate="false" test_ref="oval:org.mitre.oval:tst:2474"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mikmod is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:2473"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:644" version="2" class="vulnerability">
      <metadata>
        <title>License Logging Service Vulnerability (Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>MDAC 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0050"/>
        <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:55.342-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:49.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
            <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
            <criterion comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
          </criteria>
          <criterion negate="true" comment="the patch kb885834 is installed (Hotfix key)" test_ref="oval:org.mitre.oval:tst:2477"/>
          <criterion comment="the version of Llssrv.exe is less than 4.0.1381.33632" test_ref="oval:org.mitre.oval:tst:2476"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="license logging service is enabled" test_ref="oval:org.mitre.oval:tst:2475"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:643" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:26.933-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:50.618-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:642" version="1" class="vulnerability">
      <metadata>
        <title>HP-Samba DACL Remote Integer Overflow Vulnerability (CIFS A.02)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154"/>
        <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-13T02:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Any of the CIFS components has a version equal to A.02.01">
          <criterion comment="CIFS-Server.CIFS-RUN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2481"/>
          <criterion comment="CIFS-Server.CIFS-UTIL with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2480"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2479"/>
          <criterion comment="CIFS-Server.CIFS-LIB with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2478"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:64" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 Trusted Domain Loophole</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0018"/>
        <description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-08-04T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:56:00.000-04:00" comment="modified wft-220 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\netlogon.dll version is less than 5.0.893.1105" negate="false" test_ref="oval:org.mitre.oval:tst:2991"/>
        <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6397" version="3" class="vulnerability">
      <metadata>
        <title>Windows XP (64-Bit) DUNZIP Integer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Compressed Folders</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0575" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0575"/>
        <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-05T12:00:00.000-04:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          <criterion comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" negate="false" test_ref="oval:org.mitre.oval:tst:272"/>
          <criterion comment="the patch q873376 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1236"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Compressed Folders with zipfldr.dll are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1235"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:639" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Office Malformed String Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-1540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1540" source="CVE"/>
        <description>MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt.  NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:33.119-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.086-04:00">ACCEPTED</status_change>
            <modified date="2007-12-29T04:31:34" comment="Added application criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-01-01T09:14:17.178-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:19:32.273-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="A vulnerable application is installed">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <extend_definition comment="Microsoft Project 2000 SR1 is installed" definition_ref="oval:org.mitre.oval:def:518"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
        </criteria>
        <criteria operator="OR">
          <criteria operator="AND" comment="The 2000 version of the Mso9.dll library.">
            <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
            <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
          </criteria>
          <criteria operator="AND" comment="The 2002 version of the Mso.dll library.">
            <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
            <criterion comment="the version of Mso.dll is less than 10.0.6804.0." test_ref="oval:org.mitre.oval:tst:141"/>
          </criteria>
          <criteria operator="AND" comment="The 2003 version of the Mso.dll library.">
            <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
            <criterion comment="the version of Mso.dll is less than 11.0.8028.0." test_ref="oval:org.mitre.oval:tst:169"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:638" version="1">
      <metadata>
        <title>MMC Redirect Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Management Console</product>
        </affected>
        <reference ref_id="CVE-2006-3643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3643" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:32.866-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="the version of mmc.exe is less than 5.0.2195.7102" test_ref="oval:org.mitre.oval:tst:193"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:637" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox and Mozilla Framed Site Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1937" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1937"/>
        <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:636" version="3" class="vulnerability">
      <metadata>
        <title>MS Excel 2000 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-15 - wft-15 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2484) fixed: xcel.exe to excel.exe.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:50.673-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
        <criterion comment="the version of excel.exe is less than 9.0.0.8216" negate="false" test_ref="oval:org.mitre.oval:tst:2484"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:634" version="2" class="vulnerability">
      <metadata>
        <title>vsftpd Fails to Integrate with TCP Wrappers</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>vsftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0135"/>
        <description>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.164-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="vsftpd version is less than 1.1.3-8" negate="false" test_ref="oval:org.mitre.oval:tst:2487"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="vsftpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2486"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:632" version="2" class="vulnerability">
      <metadata>
        <title>Office Malformed Record Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-3864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3864" source="CVE"/>
        <description>Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:49.961-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:00.469-05:00">ACCEPTED</status_change>
            <modified date="2007-12-29T04:31:34" comment="Added application criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-01-01T09:14:16.658-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:19:31.745-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="A vulnerable application is installed">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <extend_definition comment="Microsoft Project 2000 SR1 is installed" definition_ref="oval:org.mitre.oval:def:518"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
        </criteria>
        <criteria operator="OR">
          <criteria operator="AND" comment="Office 2000">
            <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
            <criterion comment="The version of mso9.dll is less than 9.0.0.8950." test_ref="oval:org.mitre.oval:tst:33"/>
          </criteria>
          <criteria operator="AND" comment="Office 2002">
            <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
            <criterion comment="The version of mso.dll is less than 10.0.6817.0." test_ref="oval:org.mitre.oval:tst:158"/>
          </criteria>
          <criteria operator="AND" comment="Office 2003">
            <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
            <criterion comment="The version of mso.dll is less than 11.0.8107.0." test_ref="oval:org.mitre.oval:tst:98"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6313" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 for Server 2003 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:22:36.346-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:50.347-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:631" version="2" class="vulnerability">
      <metadata>
        <title>up2date RPM GPG Signature Verification Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>up2date</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0546"/>
        <description>up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-03T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:48.365-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="up2date version is less than 3.1.23.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:2489"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rhnsd is running" negate="false" test_ref="oval:org.mitre.oval:tst:2488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:630" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:10.741-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:50.053-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:63" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Remote Access Service Phonebook Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Access Service (RAS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0366"/>
        <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="RAS Phonebook" negate="false" test_ref="oval:org.mitre.oval:tst:2999"/>
          <criterion comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" negate="false" test_ref="oval:org.mitre.oval:tst:2992"/>
          <criterion comment="Patch Q318138 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2997"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="RAS Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:629" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:54:00.000-04:00" comment="modified wft-95 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:22:35.315-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:49.729-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.118" negate="false" test_ref="oval:org.mitre.oval:tst:2572"/>
          <criterion comment="the patch q832894 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2571"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6272" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:22:34.823-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:49.461-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:625" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 4)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:52:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.964-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="Windows NT, 2000, or XP is installed">
            <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
            <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
          </criteria>
          <criterion comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" test_ref="oval:org.mitre.oval:tst:2490"/>
          <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" test_ref="oval:org.mitre.oval:tst:2677"/>
          <criterion comment="SmartHTML interpreter is enabled" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:624" version="2" class="vulnerability">
      <metadata>
        <title>Exchange Server 5.5 TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.382-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:53:15.979-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:20.045-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange 5.5 with SP4 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2492"/>
        <criterion comment="the version of Mapi32.dll is less than 5.5.2658.34" negate="false" test_ref="oval:org.mitre.oval:tst:2491"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:623" version="1" class="vulnerability">
      <metadata>
        <title>sysreport Plaintext Password Leak</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>sysreport</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1760"/>
        <description>sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="sysreport RPM earlier than 0:1.3.7.2-6" negate="false" test_ref="oval:org.mitre.oval:tst:2494"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/tmp is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:2493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:622" version="3" class="vulnerability">
      <metadata>
        <title>Solaris 8, 9, 10 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.491-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.160-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:46:00.662-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:47:31.744-05:00">INTERIM</status_change>
            <modified comment="Standardized title." date="2007-02-26T01:01:00.306-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:22.881-04:00">ACCEPTED</status_change>
            <modified comment="Added missing patch checks." date="2007-06-26T10:59:00.754-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </modified>
            <status_change date="2007-06-26T11:00:29.787-04:00">INTERIM</status_change>
            <status_change date="2007-07-11T15:17:33.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116965-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4028"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116966-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4069"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 118305-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3204"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 117470-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4114"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 118822-27 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3505"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 118844-28 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3302"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:62" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 mibiisa Remote Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>mibiisa</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0797"/>
        <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File mibiisa exists" negate="false" test_ref="oval:org.mitre.oval:tst:2995"/>
          <criterion comment="Patch 107709-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mibiisa running" negate="false" test_ref="oval:org.mitre.oval:tst:2993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:619" version="2" class="vulnerability">
      <metadata>
        <title>UnZip 5.0 Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>unzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0282"/>
        <description>Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.657-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.784-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="unzip version is less than 5.50-33" negate="false" test_ref="oval:org.mitre.oval:tst:2498"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/unzip is executable">
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2497"/>
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2496"/>
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2495"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:618" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 Remote Desktop Protocol (RDP) DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.349-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3750"/>
        <criterion comment="SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3342"/>
        <criterion comment="64-bit version" negate="true" test_ref="oval:org.mitre.oval:tst:3257"/>
        <criterion comment="rdpwd.sys is less than 5.1.2600.1698" negate="false" test_ref="oval:org.mitre.oval:tst:3742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:616" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 swagentd Denial of Service</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>swagentd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1389"/>
        <description>Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.134-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.789-04:00">ACCEPTED</status_change>
            <modified comment="Added title and CVE reference." date="2007-02-23T16:06:00.705-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T16:06:46.731-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.697-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.876-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.891-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Installed B.11.11 software has not been patched for c00622788" negate="false">
          <criteria operator="AND" comment="DCE-Core.DCE-CORE-SHLIB is installed without PHSS_29964 or subsequent" negate="false">
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3858"/>
            <criterion comment="Patch PHSS_29964 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3974"/>
          </criteria>
          <criteria operator="AND" comment="SW-DIST.SD-AGENT is installed without PHCO_28848 or subsequent" negate="false">
            <criterion comment="SW-DIST.SD-AGENT is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3857"/>
            <criterion comment="Patch PHCO_28848 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3831"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:615" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.969-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.625-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:52:00.850-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:52:49.873-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3641"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:614" version="2" class="vulnerability">
      <metadata>
        <title>SqirrelMail Cross-site Scripting Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>SquirrelMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0160"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.275-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="squirrelmail version is less than 1.2.11-1" negate="false" test_ref="oval:org.mitre.oval:tst:2499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6122" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Malformed EPS Filter Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office 2000</product>
          <product>Microsoft Office XP</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office Project 2002</product>
          <product>Microsoft Office Converter Pack</product>
          <product>Microsoft Works</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3019"/>
        <description>Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of an Encapsulated PostScript (EPS) file, which allows remote attackers to execute arbitrary code via a crafted EPS file, aka the "Malformed EPS Filter Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:12.779-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:26.774-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:42.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <criterion comment="Office File Converter Pack is Installed" test_ref="oval:org.mitre.oval:tst:8935"/>
        </criteria>
        <criterion comment="Gifimp32.flt version is less than 2003.1100.8165.0" test_ref="oval:org.mitre.oval:tst:8744"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6120" version="1" class="vulnerability">
      <metadata>
        <title>Snapshot Viewer Arbitrary File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Access 2000</product>
          <product>Microsoft Access 2002</product>
          <product>Microsoft Access 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2463" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2463"/>
        <description>The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message.  NOTE: this can be leveraged for code execution by writing to a Startup folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:14.243-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:25.815-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:41.961-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <criterion comment="Access 2000 SP3 or greater is installed" test_ref="oval:org.mitre.oval:tst:8805"/>
          <criterion comment="Access 2002 SP3 or greater is installed" test_ref="oval:org.mitre.oval:tst:8792"/>
          <criterion comment="Access 2003 SP2 or greater is installed" test_ref="oval:org.mitre.oval:tst:9131"/>
        </criteria>
        <criterion comment="Snapview.ocx version is less than 11.0.8228.0" test_ref="oval:org.mitre.oval:tst:8931"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6118" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3283"/>
        <description>Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:14.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:48.650-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:53.320-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6113" version="0" class="vulnerability">
      <metadata>
        <title>Apple iTunes Filetype Remote Off-By-One Stack Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4116"/>
        <description>Heap-based buffer overflow in iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-25T19:13:15">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2008-09-29T13:59:01.453-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          </criteria>
          <criterion comment="iTunes.exe version is less than or equal to 8.0.0.35" test_ref="oval:org.mitre.oval:tst:8982"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6104" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX Running IPFilter, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0396"/>
        <description>Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:49.345-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:53.048-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02181">
        <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        <criterion comment="IPF-HP.IPF-MIN is installed" test_ref="oval:org.mitre.oval:tst:8668"/>
        <criteria negate="true" operator="OR" comment="Patch PHNE_35545 and PHNE_35766 are installed">
          <criterion comment="Patch PHNE_35545 is installed" test_ref="oval:org.mitre.oval:tst:8875"/>
          <criterion comment="Patch PHNE_35766 is installed" test_ref="oval:org.mitre.oval:tst:9179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6100" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:610" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX AutoRAID Critical Functionality Issue</title>
        <affected family="unix">
          <platform>HP-UX 10</platform>
          <product>AutoRAID Manager</product>
        </affected>
        <reference source="MISC" ref_id="http://www.itrc.hp.com/service/cki/patchDocDisplay.do?patchId=PHCO_23261"/>
        <description>Possible unknown vulnerability or vulnerabilities in HP DiskArray Utilities with AutoRAID Manager.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.786-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.424-04:00">ACCEPTED</status_change>
            <modified comment="Added title and reference, updated description and product." date="2007-02-26T15:48:00.739-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T15:49:57.767-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.307-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.769-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.X" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.20" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 10.20" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.20" negate="false" test_ref="oval:org.mitre.oval:tst:3807"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.20" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.20" negate="false" test_ref="oval:org.mitre.oval:tst:3807"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 10.01" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:3581"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.01" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:3581"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.10" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 10.10" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:3985"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.10" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:3985"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.30" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 10.30" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.30" negate="false" test_ref="oval:org.mitre.oval:tst:3461"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.30" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.30" negate="false" test_ref="oval:org.mitre.oval:tst:3461"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.ADMN-ENG-A-MAN or OS-Core.C2400-UTIL is installed" negate="false">
          <criterion comment="OS-Core.ADMN-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3370"/>
          <criterion comment="OS-Core.C2400-UTIL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3376"/>
        </criteria>
        <criterion comment="Patch PHCO_23261 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3674"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:61" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Remote Access Service Phonebook Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Remote Access Service (RAS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0366"/>
        <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criterion negate="true" comment="this is an NT Terminal Server" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="RAS Phonebook" test_ref="oval:org.mitre.oval:tst:2999"/>
          <criterion comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" test_ref="oval:org.mitre.oval:tst:2998"/>
          <criterion negate="true" comment="Patch Q318138 Installed" test_ref="oval:org.mitre.oval:tst:2997"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="RAS Enabled" test_ref="oval:org.mitre.oval:tst:2996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6095" version="1" class="vulnerability">
      <metadata>
        <title>Event System Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1457"/>
        <description>The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:24.008-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:23.999-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:40.682-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2000.2.3550.0" test_ref="oval:org.mitre.oval:tst:9053"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.4414.320" test_ref="oval:org.mitre.oval:tst:9013"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.4414.706" test_ref="oval:org.mitre.oval:tst:9019"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.4720.3129" test_ref="oval:org.mitre.oval:tst:9147"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.4720.4282" test_ref="oval:org.mitre.oval:tst:8200"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.4720.3129" test_ref="oval:org.mitre.oval:tst:9147"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.4720.4282" test_ref="oval:org.mitre.oval:tst:8200"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.4720.3129" test_ref="oval:org.mitre.oval:tst:9147"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.4720.4282" test_ref="oval:org.mitre.oval:tst:8200"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.6930.16677" test_ref="oval:org.mitre.oval:tst:9038"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.6931.18057" test_ref="oval:org.mitre.oval:tst:8968"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 2001.12.6931.18057" test_ref="oval:org.mitre.oval:tst:8968"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:609" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Remote Desktop Protocol (RDP) DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.579-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.082-04:00">ACCEPTED</status_change>
            <modified comment="Corrected tst:3429. Removed reference to ste:3948. Deprecated ste:3948" date="2007-02-12T10:38:00.383-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:40:21.704-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.135-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4033"/>
        <criterion comment="any SP is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3429"/>
        <criterion comment="rdpwd.sys is less than 5.2.3790.348" negate="false" test_ref="oval:org.mitre.oval:tst:3978"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6089" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Cross Site Scripting (XSS) or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4465"/>
        <description>Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset.  NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-28T13:04:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:21.198-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:29.076-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9113"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8969"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPCH32.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9088"/>
            <criterion comment="hpuxwsAPCH32.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9123"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8990"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9023"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8708"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9120"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8971"/>
            <criterion comment="hpuxwsAPCH32.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9208"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9146"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6085" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris SSH May Allow Unauthorized Access to X11 Sessions</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1483" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1483"/>
        <description>OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-25T11:33:40.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:27.939-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:28.608-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237444">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 114356-14 or later installed" test_ref="oval:org.mitre.oval:tst:9096"/>
            <criterion comment="X11Forwarding is enabled" test_ref="oval:org.mitre.oval:tst:9067"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237444">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114357-13 or later installed" test_ref="oval:org.mitre.oval:tst:9157"/>
            <criterion comment="X11Forwarding is enabled" test_ref="oval:org.mitre.oval:tst:9067"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237444">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 126133-03 or later installed" test_ref="oval:org.mitre.oval:tst:9197"/>
            <criterion negate="true" comment="X11Forwarding is not enabled" test_ref="oval:org.mitre.oval:tst:9165"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237444">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 126134-03 or later installed" test_ref="oval:org.mitre.oval:tst:9048"/>
            <criterion negate="true" comment="X11Forwarding is not enabled" test_ref="oval:org.mitre.oval:tst:9165"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="sshd running" test_ref="oval:org.mitre.oval:tst:484"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6084" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Cross Site Scripting (XSS) or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364"/>
        <description>The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-28T13:04:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:28.294-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:28.002-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9113"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8969"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPCH32.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9088"/>
            <criterion comment="hpuxwsAPCH32.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9123"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8990"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9023"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8708"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9120"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8971"/>
            <criterion comment="hpuxwsAPCH32.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9208"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9146"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:608" version="2" class="vulnerability">
      <metadata>
        <title>IE6 for Server 2003 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:22:33.293-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:49.039-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.327" test_ref="oval:org.mitre.oval:tst:2501"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2440" test_ref="oval:org.mitre.oval:tst:2500"/>
            </criteria>
            <criteria operator="AND" comment="    a vulnerable version of mshtml.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2440" test_ref="oval:org.mitre.oval:tst:2500"/>
            </criteria>
          </criteria>
          <criterion negate="true" comment="the patch kb883939 is installed" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion negate="true" comment="use machine settings rather than individual user settings" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6078" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2930" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2930"/>
        <description>Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:14.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:49.621-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:52.468-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:607" class="vulnerability" version="1">
      <metadata>
        <title>Workstation Service Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4691"/>
        <description>Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:00.053-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:48.840-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wkssvc.dll is less than 5.0.2195.7108" test_ref="oval:org.mitre.oval:tst:73"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of wkssvc.dll is less than 5.1.2600.2976" test_ref="oval:org.mitre.oval:tst:113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6060" version="1" class="vulnerability">
      <metadata>
        <title>IPsec Policy Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2246" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2246"/>
        <description>Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:24.930-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:23.688-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:40.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9135"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.6001.18094" test_ref="oval:org.mitre.oval:tst:8911"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.6001.18094" test_ref="oval:org.mitre.oval:tst:8911"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:606" version="3" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:51:00.000-04:00" comment="modified wft-12 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.964-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:05:38.476-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:49.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
          <criterion comment="the version of shtml.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2708"/>
          <criterion comment="the patch q810217 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2707"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2706"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6055" version="0" class="vulnerability">
      <metadata>
        <title>GDI+ VML Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Office 2002</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Visio 2000</product>
          <product>Microsoft Visual Studio .NET 2005</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5348" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5348"/>
        <description>Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T13:58:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-09-12T12:48:55.613-04:00">DRAFT</status_change>
            <modified comment="Fixed string literal for regular expression compatibility." date="2008-09-19T16:49:00.088-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:9115"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.5581" test_ref="oval:org.mitre.oval:tst:9133"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.3790.4278" test_ref="oval:org.mitre.oval:tst:8473"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.3790.3126" test_ref="oval:org.mitre.oval:tst:8746"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.6000.16683" test_ref="oval:org.mitre.oval:tst:8978"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="Gdiplus.dll version is less than 6.0.6001.18065" test_ref="oval:org.mitre.oval:tst:9190"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Gdiplus.dll version is less than 6.0.6001.18065" test_ref="oval:org.mitre.oval:tst:9190"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Vgx.dll version is less than 6.0.2800.1612" test_ref="oval:org.mitre.oval:tst:9041"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed" definition_ref="oval:org.mitre.oval:def:2136"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:9085"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:8275"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:8449"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          <criterion comment="Ogl.dll version is less than 12.0.6325.5000" test_ref="oval:org.mitre.oval:tst:9231"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visual Studio 2005 is installed." definition_ref="oval:org.mitre.oval:def:426"/>
          <criterion comment="ReportViewerLP.exe version is less than 2.0.50727.1843" test_ref="oval:org.mitre.oval:tst:8287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:605" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Telnet Environment Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Services for UNIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1205"/>
        <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="a vulnerable version of telnet.exe exists">
          <criteria operator="AND" comment="for specific Windows configurations a vulnerable version of telnet.exe exists">
            <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="the version of telnet.exe is less than 5.2.3790.329" test_ref="oval:org.mitre.oval:tst:2504"/>
          </criteria>
          <criteria operator="AND" comment="  for specific Windows configurations a vulnerable version of telnet.exe exists">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="the version of telnet.exe is less than 5.2.3790.2442" test_ref="oval:org.mitre.oval:tst:2503"/>
          </criteria>
          <criteria operator="AND" comment="  for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of telnet.exe exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
            <criterion comment="the version of telnet.exe is less than 5.2.3790.2442" test_ref="oval:org.mitre.oval:tst:2503"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="the patch KB896428 is installed" test_ref="oval:org.mitre.oval:tst:2502"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6048" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP4 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:45.715-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:48.581-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6040" version="0" class="vulnerability">
      <metadata>
        <title>GDI+ EMF Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Office 2002</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Visio 2000</product>
          <product>Microsoft Visual Studio .NET 2005</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3012"/>
        <description>gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T13:58:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-09-12T12:48:56.577-04:00">DRAFT</status_change>
            <modified comment="Fixed string literal for regular expression compatibility." date="2008-09-19T16:49:00.088-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:9115"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.5581" test_ref="oval:org.mitre.oval:tst:9133"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.3790.4278" test_ref="oval:org.mitre.oval:tst:8473"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.3790.3126" test_ref="oval:org.mitre.oval:tst:8746"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.6000.16683" test_ref="oval:org.mitre.oval:tst:8978"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="Gdiplus.dll version is less than 6.0.6001.18065" test_ref="oval:org.mitre.oval:tst:9190"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Gdiplus.dll version is less than 6.0.6001.18065" test_ref="oval:org.mitre.oval:tst:9190"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Vgx.dll version is less than 6.0.2800.1612" test_ref="oval:org.mitre.oval:tst:9041"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed" definition_ref="oval:org.mitre.oval:def:2136"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:9085"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:8275"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:8449"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          <criterion comment="Ogl.dll version is less than 12.0.6325.5000" test_ref="oval:org.mitre.oval:tst:9231"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visual Studio 2005 is installed." definition_ref="oval:org.mitre.oval:def:426"/>
          <criterion comment="ReportViewerLP.exe version is less than 2.0.50727.1843" test_ref="oval:org.mitre.oval:tst:8287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6035" version="0" class="vulnerability">
      <metadata>
        <title>Apple iTunes Local Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3636" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3636"/>
        <description>Integer overflow in an unspecified third-party driver bundled with Apple iTunes before 8.0 on Windows allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-17T13:25:15">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2008-09-22T11:09:15.057-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          </criteria>
          <criterion comment="iTunes.exe version is less than 8.0.0.35" test_ref="oval:org.mitre.oval:tst:9151"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6031" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.5, SP2 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T07:54:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:603" version="2" class="vulnerability">
      <metadata>
        <title>Sendmail BO in prescan Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.124-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-9.90" negate="false" test_ref="oval:org.mitre.oval:tst:2518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6025" version="0" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2258" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2258"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order" with "particular functions ... performed on" document objects, aka "HTML Objects Memory Corruption Vulnerability" or "Table Layout Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2257.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:29.725-04:00">DRAFT</status_change>
            <modified comment="Replaced CVE-2008-2257 with CVE-2008-2258" date="2008-08-26T10:42:00.546-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-09-15T04:00:27.219-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3866.2000" test_ref="oval:org.mitre.oval:tst:8949"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6022" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX running CDE, Local Increased Privilege, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0772"/>
        <description>Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:51.351-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:51.956-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:9060"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_24098 is installed" test_ref="oval:org.mitre.oval:tst:8626"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
          </criteria>
          <criteria negate="true" operator="OR" comment="Patch PHSS_24087 and PHSS_24091 are installed">
            <criterion comment="Patch PHSS_24087 is installed" test_ref="oval:org.mitre.oval:tst:9194"/>
            <criterion comment="Patch PHSS_24091 is installed" test_ref="oval:org.mitre.oval:tst:9148"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8916"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_23797 is installed" test_ref="oval:org.mitre.oval:tst:9212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6019" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Office WPG Image File Heap Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office 2000</product>
          <product>Microsoft Office XP</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office Project 2002</product>
          <product>Microsoft Office Converter Pack</product>
          <product>Microsoft Works</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3460" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3460"/>
        <description>WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfect Graphics (WPG) file, which allows remote attackers to execute arbitrary code via a crafted WPG file, aka the "WPG Image File Heap Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:31.086-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:22.885-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:39.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <criterion comment="Office File Converter Pack is Installed" test_ref="oval:org.mitre.oval:tst:8935"/>
        </criteria>
        <criterion comment="Gifimp32.flt version is less than 2003.1100.8165.0" test_ref="oval:org.mitre.oval:tst:8744"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6018" version="0" class="vulnerability">
      <metadata>
        <title>Windows Media Encoder Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Media Encoder</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3008"/>
        <description>Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T13:58:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-09-10T14:10:13.887-04:00">DRAFT</status_change>
            <modified comment="Corrected Windows Server 2008 inventory to Windows Vista 32bit" date="2008-09-12T11:21:00.875-04:00">
              <contributor organization="Secure Elements, Inc">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-09-29T04:00:50.871-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="Wmex.dll version is greater than or equal to  9.0.0.0" test_ref="oval:org.mitre.oval:tst:8780"/>
          <criterion comment="Wmex.dll version is less than to  10.0.0.0" test_ref="oval:org.mitre.oval:tst:8858"/>
          <criterion comment="Wmex.dll version is less than 9.0.0.3359" test_ref="oval:org.mitre.oval:tst:8469"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="Wmex.dll version is greater than or equal to  10.0.0.0" test_ref="oval:org.mitre.oval:tst:8587"/>
          <criterion comment="Wmex.dll version is less than to  10.0.0.0" test_ref="oval:org.mitre.oval:tst:8887"/>
          <criterion comment="Wmex.dll version is less than 10.0.0.3817" test_ref="oval:org.mitre.oval:tst:9030"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6004" version="0" class="vulnerability">
      <metadata>
        <title>GDI+ WMF Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Office 2002</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Visio 2000</product>
          <product>Microsoft Visual Studio .NET 2005</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3014"/>
        <description>Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T13:58:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:02.175-04:00">DRAFT</status_change>
            <modified comment="Fixed string literal for regular expression compatibility." date="2008-09-19T16:49:00.088-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:9115"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.5581" test_ref="oval:org.mitre.oval:tst:9133"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.3790.4278" test_ref="oval:org.mitre.oval:tst:8473"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.3790.3126" test_ref="oval:org.mitre.oval:tst:8746"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.6000.16683" test_ref="oval:org.mitre.oval:tst:8978"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="Gdiplus.dll version is less than 6.0.6001.18065" test_ref="oval:org.mitre.oval:tst:9190"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Gdiplus.dll version is less than 6.0.6001.18065" test_ref="oval:org.mitre.oval:tst:9190"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Vgx.dll version is less than 6.0.2800.1612" test_ref="oval:org.mitre.oval:tst:9041"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed" definition_ref="oval:org.mitre.oval:def:2136"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:9085"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:8275"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:8449"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          <criterion comment="Ogl.dll version is less than 12.0.6325.5000" test_ref="oval:org.mitre.oval:tst:9231"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visual Studio 2005 is installed." definition_ref="oval:org.mitre.oval:def:426"/>
          <criterion comment="ReportViewerLP.exe version is less than 2.0.50727.1843" test_ref="oval:org.mitre.oval:tst:8287"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:600" version="1">
      <metadata>
        <title>Mailslot Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating Ssytem</product>
        </affected>
        <reference ref_id="CVE-2006-1314" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1314" source="CVE"/>
        <description>Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:32.388-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.512-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of srv.sys is less than 5.0.2195.7087" negate="false" test_ref="oval:org.mitre.oval:tst:64"/>
        </criteria>
        <criteria comment="WinXP,SP1 (32-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.1832" negate="false" test_ref="oval:org.mitre.oval:tst:23"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.2893" negate="false" test_ref="oval:org.mitre.oval:tst:127"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" negate="false" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.526" negate="false" test_ref="oval:org.mitre.oval:tst:97"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" negate="false" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:60" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8 AdminTool Media Installation Path Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0088"/>
        <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:23:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:32.137-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1726, which had been badly mangled during conversion from OVAL 4.2 to 5.0.  Operation set to pattern match on path, and terminal regexp anchor moved from filename to path." date="2007-01-22T16:24:00.728-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:26:01.046-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:48.356-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6" version="2" class="vulnerability">
      <metadata>
        <title>CUPS Partial Print DOS</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>CUPS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0195"/>
        <description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.350-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cups version is less than 1.1.17-13.3" negate="false" test_ref="oval:org.mitre.oval:tst:3147"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="cupsd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:3146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5997" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft PICT Filter Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office 2000</product>
          <product>Microsoft Office XP</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office Project 2002</product>
          <product>Microsoft Office Converter Pack</product>
          <product>Microsoft Works</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3021"/>
        <description>Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file with an invalid bits_per_pixel field, aka the "PICT Filter Parsing Vulnerability," a different vulnerability than CVE-2008-3018.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:31.855-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:21.688-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:39.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <criterion comment="Office File Converter Pack is Installed" test_ref="oval:org.mitre.oval:tst:8935"/>
        </criteria>
        <criterion comment="Gifimp32.flt version is less than 2003.1100.8165.0" test_ref="oval:org.mitre.oval:tst:8744"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5995" version="0" class="vulnerability">
      <metadata>
        <title>Windows Messenger Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Messenger 4.7</product>
          <product>Windows Messenger 5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0082"/>
        <description>An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:34.394-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:20.368-04:00">INTERIM</status_change>
            <modified comment="updated the version of msgsc.dll to 5.1.0.715." date="2008-09-19T16:46:00.083-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Windows Messenger 4.7 is installed" definition_ref="oval:org.mitre.oval:def:6101"/>
          <criterion comment="the version of msgsc.dll is less than 4.7.0.3002" test_ref="oval:org.mitre.oval:tst:9100"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Windows Messenger 5.1 is installed" definition_ref="oval:org.mitre.oval:def:5691"/>
          <criterion comment="the version of msgsc.dll is less than 5.1.0.715" test_ref="oval:org.mitre.oval:tst:8944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6101" version="1" class="inventory">
      <metadata>
        <title>Windows Messenger 4.7 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office:2000"/>
        <description>The application Windows Messenger 4.7 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:33.603-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:25.460-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:41.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Messenger 4.7 is installed" test_ref="oval:org.mitre.oval:tst:8484"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5988" version="0" class="vulnerability">
      <metadata>
        <title>tftp buffer overflow allows local users to gain priveleges</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6717"/>
        <description>Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-12T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-12T12:50:00.316-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:50.400-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2007-6717">
          <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
          <criterion negate="true" comment="All filesets for APAR IZ03054 are installed" test_ref="oval:org.mitre.oval:tst:9024"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-06 meets CVE-2007-6717">
          <extend_definition comment="IBM AIX 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:4813"/>
          <criterion negate="true" comment="All filesets for APAR IZ03060 are installed" test_ref="oval:org.mitre.oval:tst:9345"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2007-6717">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ03392 are installed" test_ref="oval:org.mitre.oval:tst:8827"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5986" version="0" class="vulnerability">
      <metadata>
        <title>GDI+ GIF Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Office 2002</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Visio 2000</product>
          <product>Microsoft Visual Studio .NET 2005</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3013"/>
        <description>gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T13:58:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:03.099-04:00">DRAFT</status_change>
            <modified comment="Fixed string literal for regular expression compatibility." date="2008-09-19T16:49:00.088-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:9115"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.5581" test_ref="oval:org.mitre.oval:tst:9133"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.3790.4278" test_ref="oval:org.mitre.oval:tst:8473"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.3790.3126" test_ref="oval:org.mitre.oval:tst:8746"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Gdiplus.dll version is less than 5.2.6000.16683" test_ref="oval:org.mitre.oval:tst:8978"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="Gdiplus.dll version is less than 6.0.6001.18065" test_ref="oval:org.mitre.oval:tst:9190"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Gdiplus.dll version is less than 6.0.6001.18065" test_ref="oval:org.mitre.oval:tst:9190"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Vgx.dll version is less than 6.0.2800.1612" test_ref="oval:org.mitre.oval:tst:9041"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed" definition_ref="oval:org.mitre.oval:def:2136"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:9085"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:8275"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdiplus.dll version is less than 5.1.3102.3352" test_ref="oval:org.mitre.oval:tst:8449"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          <criterion comment="Ogl.dll version is less than 12.0.6325.5000" test_ref="oval:org.mitre.oval:tst:9231"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visual Studio 2005 is installed." definition_ref="oval:org.mitre.oval:def:426"/>
          <criterion comment="ReportViewerLP.exe version is less than 2.0.50727.1843" test_ref="oval:org.mitre.oval:tst:8287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:598" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running xterm Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3779"/>
        <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.676-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.645-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02075" date="2008-07-14T10:21:00.902-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:23:55.918-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.071-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34102 is installed" test_ref="oval:org.mitre.oval:tst:8317"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34160 is installed" test_ref="oval:org.mitre.oval:tst:8362"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34159 is installed" test_ref="oval:org.mitre.oval:tst:8389"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5971" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ftpd, Remote Privileged Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1668" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1668"/>
        <description>ftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which PAM authentication can succeed even though no passwd entry is available for a user, which allows remote attackers to gain privileges, as demonstrated by a login attempt for an LDAP account when nsswitch.conf does not specify LDAP for passwd information.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-12T16:30:32.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:35.905-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:19.712-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:38.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02356">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:9029"/>
        <criterion negate="true" comment="Patch PHNE_38458 is installed" test_ref="oval:org.mitre.oval:tst:9107"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5970" version="0" class="vulnerability">
      <metadata>
        <title>Uniform Resource Locator Validation Error Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Office 2002</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office 2007</product>
          <product>Microsoft Office 2007 Compatibility Pack</product>
          <product>Microsoft OneNote 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3007"/>
        <description>Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T13:58:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-09-10T14:10:17.649-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:49.775-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="Mso.dll version is less than 10.0.6845.0" test_ref="oval:org.mitre.oval:tst:9154"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="Mso.dll version is less than 11.0.8221.0" test_ref="oval:org.mitre.oval:tst:8952"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          <criterion comment="Mso.dll version is less than 12.0.6320.5000" test_ref="oval:org.mitre.oval:tst:8962"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="OneNote 2007 is installed" test_ref="oval:org.mitre.oval:tst:8374"/>
          <criterion comment="Onenote.exe version is less than 12.0.6316.5000" test_ref="oval:org.mitre.oval:tst:8591"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:597" version="2" class="vulnerability">
      <metadata>
        <title>Denial of Service in Sendmail via the enhdnsbl Feature</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0688"/>
        <description>The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.069-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:36.804-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-6.90" negate="false" test_ref="oval:org.mitre.oval:tst:2517"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sendmail is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2516"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5960" version="0" class="vulnerability">
      <metadata>
        <title>SUNRAS Plugin of Gimp Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2356"/>
        <description>Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-11T11:37:41.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:06.257-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:49.434-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-22 or later installed" test_ref="oval:org.mitre.oval:tst:8701"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 121775-01 or later installed" test_ref="oval:org.mitre.oval:tst:9219"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-22 or later installed" test_ref="oval:org.mitre.oval:tst:8353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:596" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 or 11.23 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.438-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.897-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:53:00.683-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:54:12.704-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5958" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX running CDE, Local Increased Privilege, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0551"/>
        <description>Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:51.818-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:48.724-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8916"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_24098 is installed" test_ref="oval:org.mitre.oval:tst:8626"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
          </criteria>
          <criteria negate="true" operator="OR" comment="Patch PHSS_24087 and PHSS_24091 are installed">
            <criterion comment="Patch PHSS_24087 is installed" test_ref="oval:org.mitre.oval:tst:9194"/>
            <criterion comment="Patch PHSS_24091 is installed" test_ref="oval:org.mitre.oval:tst:9148"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8916"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_23797 is installed" test_ref="oval:org.mitre.oval:tst:9212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5951" version="1" class="vulnerability">
      <metadata>
        <title>Excel Credential Caching Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2000</product>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft SharePoint Server 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3003"/>
        <description>Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:36.632-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:18.822-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:38.513-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Excel 2007 is installed" test_ref="oval:org.mitre.oval:tst:8518"/>
        <criterion comment="Excel.exe version is less than 12.0.6323.5000" test_ref="oval:org.mitre.oval:tst:8965"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:595" version="2" class="vulnerability">
      <metadata>
        <title>Potential BO in Ruleset Parsing for Sendmail</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0681" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0681"/>
        <description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.782-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:36.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-9.90" negate="false" test_ref="oval:org.mitre.oval:tst:2518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:594" version="4" class="vulnerability">
      <metadata>
        <title>Windows Messenger 6 libpng Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
        <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-11-24T12:00:00.000-04:00" comment="Added wrt-620 to see if MSN Messenger 6.2 is installed.  Changed wrt-195 to check for 6.2.0205 or later.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Added wrt-195.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2359" date="2007-03-06T08:06:00.649-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-06T08:07:06.751-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.723-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1436" date="2007-04-23T12:05:00.002-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:31:50.117-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1435" date="2007-04-23T12:05:00.788-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:07.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MSN Messenger 6.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2520"/>
        <criterion comment="MSN Messenger 6.2.0205 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2519"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5938" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS HTTP Configuration Interface Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0380"/>
        <description>The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:13.003-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:06.657-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:58.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2000-0380">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8807"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8890"/>
        <criterion comment="config contains: ^\s*ip http server" test_ref="oval:org.mitre.oval:tst:8123"/>
        <criterion negate="true" comment="config contains: ^\s*no ip http server" test_ref="oval:org.mitre.oval:tst:8920"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5936" version="0" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Filetype Remote Off-By-One Stack Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4116"/>
        <description>Heap-based buffer overflow in Apple QuickTime 7.5.5 (7.55.90.70) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-24T20:44:22">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2008-09-29T13:59:01.926-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          </criteria>
          <criterion comment="QuickTimePlayer.exe version is less than or equal to 7.55.90.70" test_ref="oval:org.mitre.oval:tst:9317"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5932" version="0" class="vulnerability">
      <metadata>
        <title>IBM AIX 'swcons' Insecure File Creation Vulnerability</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4018"/>
        <description>swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors.  NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-16T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-19T17:09:31.133-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5.2 meets CVE-2008-4018">
          <extend_definition comment="IBM AIX 5.2 is installed" definition_ref="oval:org.mitre.oval:def:5189"/>
          <criterion negate="true" comment="All filesets for APAR IZ18335 are installed" test_ref="oval:org.mitre.oval:tst:9163"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5.3 meets CVE-2008-4018">
          <extend_definition comment="IBM AIX 5.3 is installed" definition_ref="oval:org.mitre.oval:def:5325"/>
          <criterion negate="true" comment="All filesets for APAR IZ18334 are installed" test_ref="oval:org.mitre.oval:tst:9292"/>
          <criterion negate="true" comment="All filesets for APAR IZ18338 are installed" test_ref="oval:org.mitre.oval:tst:9251"/>
          <criterion negate="true" comment="All filesets for APAR IZ18339 are installed" test_ref="oval:org.mitre.oval:tst:9010"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6.1 meets CVE-2008-4018">
          <extend_definition comment="IBM AIX 6.1 is installed" definition_ref="oval:org.mitre.oval:def:5267"/>
          <criterion negate="true" comment="All filesets for APAR iZ28943 are installed" test_ref="oval:org.mitre.oval:tst:9324"/>
          <criterion negate="true" comment="All filesets for APAR IZ18341 are installed" test_ref="oval:org.mitre.oval:tst:9161"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:593" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.302-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.734-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:52:00.734-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:52:28.751-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.562-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.589-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.534-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS-RUN for B.11.23 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3687"/>
        <criterion comment="Patch PHNE_33414 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3428"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5926" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 NNTP Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0574"/>
        <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T08:58:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:59.853-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
          <criterion comment="the version of nntpsvc.dll is less than 5.0.2195.6972" negate="false" test_ref="oval:org.mitre.oval:tst:274"/>
          <criterion comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:273"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5923" version="0" class="vulnerability">
      <metadata>
        <title>Microsoft Color Management System Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2245"/>
        <description>Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:38.460-04:00">DRAFT</status_change>
            <modified comment="Replaced CVE-2008-2463 with CVE-2008-2245" date="2008-08-26T10:39:00.148-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-09-15T04:00:26.271-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of mscms.dll is less than 5.0.2195.7162" test_ref="oval:org.mitre.oval:tst:8571"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of mscms.dll is less than 5.1.2600.3396" test_ref="oval:org.mitre.oval:tst:8739"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of mscms.dll is less than 5.1.2600.5627" test_ref="oval:org.mitre.oval:tst:8660"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of mscms.dll is less than 5.2.3790.3163" test_ref="oval:org.mitre.oval:tst:8995"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of mscms.dll is less than 5.2.3790.4320" test_ref="oval:org.mitre.oval:tst:9047"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <criterion comment="the version of mscms.dll is less than 5.2.3790.3163" test_ref="oval:org.mitre.oval:tst:8995"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="the version of mscms.dll is less than 5.2.3790.4320" test_ref="oval:org.mitre.oval:tst:9047"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          <criterion comment="the version of mscms.dll is less than 5.2.3790.3163" test_ref="oval:org.mitre.oval:tst:8995"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <criterion comment="the version of mscms.dll is less than 5.2.3790.4320" test_ref="oval:org.mitre.oval:tst:9047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5920" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX Running rpcbind, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0165"/>
        <description>A potential security vulnerability has been identified with HP-UX running rpcbind. The vulnerability could be remotely exploited to create a Denial of Service (DoS) .</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-22T12:50:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-29T13:59:02.797-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02370">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:9268"/>
            <criterion comment="NFS.NFS-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8790"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_37110 is installed" test_ref="oval:org.mitre.oval:tst:8791"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02370">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:9268"/>
            <criterion comment="NFS.NFS-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8790"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_36982 is installed" test_ref="oval:org.mitre.oval:tst:9288"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:592" version="1" class="vulnerability">
      <metadata>
        <title>rwho daemon Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Licence Logging Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1351"/>
        <description>Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed">
            <criteria operator="OR" comment="Solaris 7 or 8 installed">
              <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
              <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed">
              <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
              <criterion comment="Remote Network Server Commands - Usr (SUNWrcmds) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2525"/>
            </criteria>
          </criteria>
          <criterion comment="Patch 118239-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2524"/>
          <criterion comment="Patch 116984-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2523"/>
          <criterion comment="Patch 117455-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2522"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.rwhod is running" negate="false" test_ref="oval:org.mitre.oval:tst:2521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5918" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS HTTP Server Query Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0984"/>
        <description>The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:14.159-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:06.376-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:57.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2000-0984">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8864"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8803"/>
        <criterion comment="config contains: ^\s*ip http server" test_ref="oval:org.mitre.oval:tst:8123"/>
        <criterion negate="true" comment="config contains: ^\s*no ip http server" test_ref="oval:org.mitre.oval:tst:8920"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5913" version="1" class="vulnerability">
      <metadata>
        <title>HTML Component Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2259" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2259"/>
        <description>Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print preview, which allows remote attackers to execute arbitrary code via unknown vectors, aka "HTML Component Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:39.306-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:16.985-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:37.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3866.2000" test_ref="oval:org.mitre.oval:tst:8949"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:591" version="4" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:51:00.000-04:00" comment="modified wft-12 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.964-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:05:37.542-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:49.036-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:54.764-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:49.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criterion comment="the version of shtml.dll is less than 4.00.02.7523" test_ref="oval:org.mitre.oval:tst:2708"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (WinNT)" test_ref="oval:org.mitre.oval:tst:2526"/>
          <criterion comment="SmartHTML interpreter is enabled" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5908" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GIMP(1) May Lead to Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3404"/>
        <description>Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T10:55:30.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-09T11:57:57.533-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:47.920-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 200070">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-18 or later installed" test_ref="oval:org.mitre.oval:tst:8318"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 200070">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-18 or later installed" test_ref="oval:org.mitre.oval:tst:9239"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:590" version="1">
      <metadata>
        <title>Microsoft Publisher Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Publisher</product>
        </affected>
        <reference ref_id="CVE-2006-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0001" source="CVE"/>
        <description>Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-21T07:56:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <modified date="2006-09-25T03:45:32" comment="Modified obj:94 (used by tst:29, tst:36, and tst:168) to reference var:297 instead of var:231.  New version uses 'App Path' regkey for mspub.exe, instead of leveraging regkey for excel.exe.  Thanks to Anna Min of BigFix for reporting the issue.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-10-10T20:40:00.262-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:49.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Publisher 2000" operator="AND">
          <extend_definition comment="Microsoft Publisher 2000 is installed" definition_ref="oval:org.mitre.oval:def:427"/>
          <criterion comment="the version of mspub.exe is less than 9.0.0.8930" test_ref="oval:org.mitre.oval:tst:36"/>
        </criteria>
        <criteria comment="Publisher 2002" operator="AND">
          <extend_definition comment="Microsoft Publisher 2002 is installed" definition_ref="oval:org.mitre.oval:def:734"/>
          <criterion comment="the version of mspub.exe is less than 10.0.6815.0" test_ref="oval:org.mitre.oval:tst:168"/>
        </criteria>
        <criteria comment="Publisher 2003" operator="AND">
          <extend_definition comment="Microsoft Publisher 2003 is installed" definition_ref="oval:org.mitre.oval:def:239"/>
          <criterion comment="the version of mspub.exe is less than 11.0.8103.0" test_ref="oval:org.mitre.oval:tst:29"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:59" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Windows RPC Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1561"/>
        <description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" negate="false" test_ref="oval:org.mitre.oval:tst:3002"/>
        <criterion comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3001"/>
        <criterion comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3000"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5897" version="1" class="vulnerability">
      <metadata>
        <title>Word Record Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2244"/>
        <description>Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:41.426-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:16.452-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:37.045-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="Word 2002 SP3 or greater is installed" test_ref="oval:org.mitre.oval:tst:8156"/>
          <criterion comment="WinWord.exe version is less than 10.0.6846.0" test_ref="oval:org.mitre.oval:tst:9074"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="Word 2003 SP2 or greater is installed" test_ref="oval:org.mitre.oval:tst:9033"/>
          <criterion comment="WinWord.exe version is less than 11.0.8227.0" test_ref="oval:org.mitre.oval:tst:8938"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5892" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Protocol Check Design Error</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0929" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0929"/>
        <description>Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:14.623-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:06.117-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:57.235-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-0929">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8757"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8245"/>
        <criterion comment="config contains: ip inspect" test_ref="oval:org.mitre.oval:tst:9064"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5886" version="1" class="vulnerability">
      <metadata>
        <title>URL Parsing Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Outlook Express</product>
          <product>Microsoft Mail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1448"/>
        <description>The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to UNC share pathnames, which allows remote attackers to bypass intended access restrictions and read arbitrary files via an mhtml: URI in conjunction with a redirection, aka "URL Parsing Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:47.644-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:14.157-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:36.238-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Outlook Express 5.5 SP2 on Win 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Outlook Express 5.5 SP2 is installed." definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 5.50.4990.2500" test_ref="oval:org.mitre.oval:tst:8947"/>
        </criteria>
        <criteria operator="AND" comment="Outlook Express 6 SP1 on Win 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Outlook Express 6 SP1 is installed." definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.2800.1933" test_ref="oval:org.mitre.oval:tst:8366"/>
        </criteria>
        <criteria operator="AND" comment="Outlook Express 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.2900.3350" test_ref="oval:org.mitre.oval:tst:8951"/>
        </criteria>
        <criteria operator="AND" comment="Outlook Express 6 on Win XP SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.2900.5579" test_ref="oval:org.mitre.oval:tst:8248"/>
        </criteria>
        <criteria operator="AND" comment="Outlook Express 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.3790.3168" test_ref="oval:org.mitre.oval:tst:9171"/>
        </criteria>
        <criteria operator="AND" comment="Outlook Express 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.3790.4325" test_ref="oval:org.mitre.oval:tst:9185"/>
        </criteria>
        <criteria operator="AND" comment="Outlook Express 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP2 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:1799"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.3790.4325" test_ref="oval:org.mitre.oval:tst:9185"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista">
          <criteria operator="OR" comment="Windows Vista 32-bit or 64-bit">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.6000.16669" test_ref="oval:org.mitre.oval:tst:8459"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Ipsecsvc.dll is less than 6.0.6001.18049" test_ref="oval:org.mitre.oval:tst:9051"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5885" version="1" class="vulnerability">
      <metadata>
        <title>Excel Indexing Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2000</product>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3004" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3004"/>
        <description>Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3; Office Excel Viewer 2003; and Office 2004 and 2008 for Mac do not properly validate index values for AxesSet records when loading Excel files, which allows remote attackers to execute arbitrary code via a crafted Excel file, aka the "Excel Indexing Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:50.355-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:13.694-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:35.589-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="Excel 2000 SP3 or greater is installed" test_ref="oval:org.mitre.oval:tst:8157"/>
          <criterion comment="Excel.exe version is less than 9.0.0.8971" test_ref="oval:org.mitre.oval:tst:8840"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="Excel 2002 SP3 or greater is installed" test_ref="oval:org.mitre.oval:tst:8677"/>
          <criterion comment="Excel.exe version is less than 10.0.6845.0" test_ref="oval:org.mitre.oval:tst:8819"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="Excel 2003 SP3 or greater is installed" test_ref="oval:org.mitre.oval:tst:8903"/>
          <criterion comment="Excel.exe version is less than 11.0.8220.0" test_ref="oval:org.mitre.oval:tst:9020"/>
        </criteria>
        <criterion comment="Xlview.exe version is less than 11.0.8220.0" test_ref="oval:org.mitre.oval:tst:8740"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5884" version="0" class="vulnerability">
      <metadata>
        <title>Manipulated Tag Files used with Solaris Text Editors May Lead to Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4131"/>
        <description>Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-24T10:35:21.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-09-29T13:59:05.488-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 110903-08 or later installed" test_ref="oval:org.mitre.oval:tst:8986"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113031-04 or later installed" test_ref="oval:org.mitre.oval:tst:9138"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120830-06 or later installed" test_ref="oval:org.mitre.oval:tst:9109"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 110904-08 or later installed" test_ref="oval:org.mitre.oval:tst:9009"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 116479-02 or later installed" test_ref="oval:org.mitre.oval:tst:9291"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120831-06 or later installed" test_ref="oval:org.mitre.oval:tst:9137"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5881" version="0" class="vulnerability">
      <metadata>
        <title>GDI+ BMP Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Office 2002</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Visio 2000</product>
          <product>Microsoft Visual Studio .NET 2005</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3015"/>
        <description>Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T13:58:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:06.488-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:47.054-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          <criterion comment="Ogl.dll version is less than 12.0.6325.5000" test_ref="oval:org.mitre.oval:tst:9231"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Visual Studio 2005 is installed." definition_ref="oval:org.mitre.oval:def:426"/>
          <criterion comment="ReportViewerLP.exe version is less than 2.0.50727.1843" test_ref="oval:org.mitre.oval:tst:8287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:588" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2621. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T20:21:00.819-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T20:22:29.138-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:48.055-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false" test_ref="oval:org.mitre.oval:tst:2686"/>
          <criterion comment="the patch q824145 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2685"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5879" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Malformed PICT Filter Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office 2000</product>
          <product>Microsoft Office XP</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office Project 2002</product>
          <product>Microsoft Office Converter Pack</product>
          <product>Microsoft Works</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3018"/>
        <description>Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file, aka the "Malformed PICT Filter Vulnerability," a different vulnerability than CVE-2008-3021.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:51.095-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:12.956-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:35.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <criterion comment="Office File Converter Pack is Installed" test_ref="oval:org.mitre.oval:tst:8935"/>
        </criteria>
        <criterion comment="Gifimp32.flt version is less than 2003.1100.8165.0" test_ref="oval:org.mitre.oval:tst:8744"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5877" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2929" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2929"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1 before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow remote attackers to inject arbitrary web script or HTML via input values that use % (percent) escaping.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:14.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:52.563-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:46.101-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5874" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS UDP 514 Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0063"/>
        <description>Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:15.001-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:05.913-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:56.968-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-1999-0063">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8596"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8788"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:587" version="2" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (64-bit Server 2003 and XP Version 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1522: Removed blank before the word Filelist in the Key.  Modified by Harvey Rubinovitz." date="2007-01-22T00:07:00.158-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-22T00:08:37.654-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:47.817-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003">
            <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
              <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.274" negate="false" test_ref="oval:org.mitre.oval:tst:2527"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2657"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5869" version="1" class="vulnerability">
      <metadata>
        <title>Cisco 7600, Catalyst 6000 and 6500 MPLS Packet DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1258" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1258"/>
        <description>Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of service (software reload) via a certain MPLS packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:15.391-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:05.715-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:56.733-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-1258">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8476"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8613"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5867" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS HTTP Server Router Administration Script Injection Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3921" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3921"/>
        <description>Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages.  NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:15.847-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:05.477-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:56.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2005-3921">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8847"/>
        <criteria operator="OR" comment="running congfig meets CVE-2005-3921">
          <criteria operator="AND">
            <criterion comment="config contains: ^\s*ip http server" test_ref="oval:org.mitre.oval:tst:8123"/>
            <criterion negate="true" comment="config contains: ^\s*no ip http server" test_ref="oval:org.mitre.oval:tst:8920"/>
          </criteria>
          <criteria operator="AND">
            <criterion comment="config contains: ^\s*ip http secure-server" test_ref="oval:org.mitre.oval:tst:8767"/>
            <criterion negate="true" comment="config contains: ^\s*no ip http secure-server" test_ref="oval:org.mitre.oval:tst:8357"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5866" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS VTY Authentication Bypass Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4632"/>
        <description>Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:16.314-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:05.216-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:55.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-4632">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8759"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8872"/>
        <criterion comment="config contains: no login" test_ref="oval:org.mitre.oval:tst:9004"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5865" version="0" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2928" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2928"/>
        <description>Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted Accept-Language HTTP header.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:13.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:53.166-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:45.418-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5862" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS 12.0 Series Internet Router Allowance for Malicious Packets Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0864"/>
        <description>Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:16.638-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:05.018-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:55.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-0864">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8175"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8762"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5860" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS UDP for IPv4/IPv6 Unspecified Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1153"/>
        <description>Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to the device.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:17.363-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:04.794-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:55.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2008-1153">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8691"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8548"/>
        <criteria operator="OR">
          <criterion comment="config contains: ipv6 address" test_ref="oval:org.mitre.oval:tst:8725"/>
          <criterion comment="config contains: ipv6 enabled" test_ref="oval:org.mitre.oval:tst:8696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:586" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 98 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 98</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-16T04:13:00.000-04:00" comment="Modified test 2528 to use obj:492 rather than obj:1443 since they were the same and this definition was the only reference to obj:1443.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2006-10-16T04:13:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 98 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2529"/>
        <criterion comment="the version of winword.exe is less than 8.0.0.9716" negate="false" test_ref="oval:org.mitre.oval:tst:2528"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5859" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Malformed PPTP Packet Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1183"/>
        <description>PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:17.795-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:04.579-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:55.148-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-1183">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8778"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8717"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5858" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Fragmented Packet IPS Evasion Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0917" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0917"/>
        <description>The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:18.098-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:04.310-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:54.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-0917">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8199"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8865"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5857" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS IPv6 Type 0 Routing Header DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0481" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0481"/>
        <description>Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:18.478-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:04.043-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:54.603-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-0481">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8879"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8736"/>
        <criteria operator="OR">
          <criterion comment="config contains: ipv6 address" test_ref="oval:org.mitre.oval:tst:8725"/>
          <criterion comment="config contains: ipv6 enabled" test_ref="oval:org.mitre.oval:tst:8696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5855" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Using libc, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1664"/>
        <description>Unspecified vulnerability in libc on HP HP-UX B.11.23 and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-07T10:53:22.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:29.603-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:11.754-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:34.470-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02355">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="ProgSupport.PROG-MIN is installed" test_ref="oval:org.mitre.oval:tst:8906"/>
            <criterion comment="OS-Core.CORE-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8378"/>
            <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8981"/>
            <criterion comment="OS-Core.C-MIN is installed" test_ref="oval:org.mitre.oval:tst:8917"/>
            <criterion comment="OS-Core.C-MIN-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8551"/>
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8680"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:9084"/>
            <criterion comment="ProgSupport.PROG2-AUX is installed" test_ref="oval:org.mitre.oval:tst:8594"/>
            <criterion comment="ProgSupport.PROG-AX-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8703"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_3804 is installed" test_ref="oval:org.mitre.oval:tst:8563"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02355">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.C-MIN is installed" test_ref="oval:org.mitre.oval:tst:8917"/>
            <criterion comment="OS-Core.C-MIN-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8551"/>
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8680"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:9084"/>
            <criterion comment="ProgSupport.PROG2-AUX is installed" test_ref="oval:org.mitre.oval:tst:8594"/>
            <criterion comment="ProgSupport.PROG-AX-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8703"/>
            <criterion comment="ProgSupport.PROG-MIN is installed" test_ref="oval:org.mitre.oval:tst:8906"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_38273 is installed" test_ref="oval:org.mitre.oval:tst:8692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5852" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Systems IOS Easy VPN Server xauth Extension Access Validation Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1057"/>
        <description>Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:18.970-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:03.811-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:54.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2005-1057">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8755"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8721"/>
        <criteria operator="OR">
          <criterion comment="config contains: crypto map \S+ client authentication list" test_ref="oval:org.mitre.oval:tst:8976"/>
          <criteria operator="AND">
            <criterion comment="config contains: crypto isakmp profile" test_ref="oval:org.mitre.oval:tst:9110"/>
            <criterion comment="config contains: crypto isakmp profile" test_ref="oval:org.mitre.oval:tst:9110"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5851" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Session Initiation Protocol (SIP) Packet Arbitrary Code Execution
          Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4294" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4294"/>
        <description>Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80102.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:19.279-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:03.605-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:54.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-4294">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8832"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8472"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:585" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 97 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 97</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-17 - wft-17 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T12:01:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-20T12:00:00.000-04:00" comment="Corrected unknown test">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified comment="Incorrect notes element updated to match comment" date="2008-02-28T09:54:00.107-05:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Word 97 is installed" test_ref="oval:org.mitre.oval:tst:2531"/>
        <criterion comment="the version of winword.exe is less than 8.0.0.9315" test_ref="oval:org.mitre.oval:tst:2530"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5849" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vendors SSH2 "ncorrect length fields" Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1357"/>
        <description>Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:19.616-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:03.369-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:53.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2002-1357">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8661"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8424"/>
        <criterion comment="config contains: crypto key generate rsa" test_ref="oval:org.mitre.oval:tst:8948"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5848" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vendors SSH2 "buffer overflow" Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1359"/>
        <description>Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:19.752-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:03.150-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:53.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2002-1359">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8661"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8424"/>
        <criterion comment="config contains: crypto key generate rsa" test_ref="oval:org.mitre.oval:tst:8948"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5845" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS SNMP Malformed Message Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0714" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0714"/>
        <description>Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly chosen UDP port), which allows remote attackers to cause a denial of service (device reload and memory corruption).</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-30T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:20.103-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:02.949-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:52.962-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2004-0714">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8964"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8643"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5840" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS 12.3 IPv6 Packet Processing Information Leakage Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4285"/>
        <description>Unspecified vulnerability in Cisco IOS and Cisco IOS XR 12.x up to 12.3, including some versions before 12.3(15) and 12.3(14)T, allows remote attackers to obtain sensitive information (partial packet contents) or cause a denial of service (router or component crash) via crafted IPv6 packets with a Type 0 routing header.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:20.454-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:02.696-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:52.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-4285">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8702"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8846"/>
        <criteria operator="OR">
          <criterion comment="config contains: ipv6 address" test_ref="oval:org.mitre.oval:tst:8725"/>
          <criterion comment="config contains: ipv6 enabled" test_ref="oval:org.mitre.oval:tst:8696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:584" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla IDN heap overrun using soft-hyphens</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2871"/>
        <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:39.060-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:21.368-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:58.657-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:06.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5839" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Node Route Processor 2 12.1 DC Authorization Circumvention Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0757" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0757"/>
        <description>Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers to obtain access via telnet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:20.802-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:02.476-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:52.026-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-0757">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8582"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8873"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5837" version="1" class="vulnerability">
      <metadata>
        <title>Excel Index Array Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2000</product>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft SharePoint Server 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3005"/>
        <description>Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:51.886-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:11.535-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:33.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion comment="Excel 2000 SP3 or greater is installed" test_ref="oval:org.mitre.oval:tst:8157"/>
          <criterion comment="Excel.exe version is less than 9.0.0.8971" test_ref="oval:org.mitre.oval:tst:8840"/>
        </criteria>
        <criteria operator="AND">
          <criterion comment="Excel 2002 SP3 or greater is installed" test_ref="oval:org.mitre.oval:tst:8677"/>
          <criterion comment="Excel.exe version is less than 10.0.6845.0" test_ref="oval:org.mitre.oval:tst:8819"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5836" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS AAA Command Authorization Bypass Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0485" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0485"/>
        <description>The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:21.325-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:02.236-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:51.590-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2006-2006-0485">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8666"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8876"/>
        <criterion comment="config contains: aaa authorization commands .*tacacs+" test_ref="oval:org.mitre.oval:tst:9042"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5835" version="1" class="vulnerability">
      <metadata>
        <title>Multiple OS TCP/IP DoS Vulnerabilities</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0016"/>
        <description>Land IP denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-01T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:21.683-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:02.032-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:50.960-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-1999-0016">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8821"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8970"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5834" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Aironet Wireless Devices DoS</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0511"/>
        <description>The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-30T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:22.316-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:01.778-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:50.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Cisco ISO meets CVE-2003-0511">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8760"/>
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8623"/>
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:9032"/>
        <criterion comment="config contains: ^\s*ip http secure-server" test_ref="oval:org.mitre.oval:tst:9043"/>
        <criterion negate="true" comment="config contains: ^\s*no ip http secure-server" test_ref="oval:org.mitre.oval:tst:8992"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5832" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Regular Expression ATOMIC.TCP DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0918" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0918"/>
        <description>The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffic) signature.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:22.698-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:01.533-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:50.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-0918">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8199"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8865"/>
        <criteria operator="OR">
          <criterion comment="config contains: ip ips \S+ in" test_ref="oval:org.mitre.oval:tst:8601"/>
          <criterion comment="config contains: ip ips \S+ out" test_ref="oval:org.mitre.oval:tst:8509"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5831" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vendor Session Initiation Protocol Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1108"/>
        <description>The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:23.038-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:01.305-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:49.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2003-1108">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8895"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8850"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5828" version="1" class="vulnerability">
      <metadata>
        <title>Cisco 6000/6500/7600 Crafted Layer 2 Frame Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0244"/>
        <description>Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:23.380-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:01.089-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:49.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2004-0244">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8738"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:9014"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5827" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS PPP CHAP Authentication Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0160"/>
        <description>Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:23.697-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:00.879-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:49.256-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-1999-0160">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8639"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8894"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5826" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Multiple Router Products Web Setup Configuration Error Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3595" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3595"/>
        <description>The default configuration of IOS HTTP server in Cisco Router Web Setup (CRWS) before 3.3.0 build 31 does not require credentials, which allows remote attackers to access the server with arbitrary privilege levels, aka bug CSCsa78190.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:24.232-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:00.647-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:48.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2006-3595">
        <criterion comment="config contains: ^\s*ip http" test_ref="oval:org.mitre.oval:tst:8515"/>
        <criterion negate="true" comment="config contains: enable secret" test_ref="oval:org.mitre.oval:tst:8603"/>
        <criterion negate="true" comment="config contains: ^\s*ip http authentication" test_ref="oval:org.mitre.oval:tst:8554"/>
        <criterion negate="true" comment="config contains: enable password" test_ref="oval:org.mitre.oval:tst:8120"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5824" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS User Enumeration via Error Messages</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0512" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0512"/>
        <description>Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:24.639-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:00.385-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:48.595-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2003-0512">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8849"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8699"/>
        <criterion negate="true" comment="config contains: aaa new-model" test_ref="oval:org.mitre.oval:tst:9089"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5823" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS CDP Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1071"/>
        <description>Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:25.284-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:01:00.121-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:48.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-1071">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8782"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8852"/>
        <criteria operator="OR" comment="running congfig meets CVE-2005-3921">
          <criteria operator="AND">
            <criterion comment="config contains: ^\s*cdp run" test_ref="oval:org.mitre.oval:tst:8706"/>
            <criterion negate="true" comment="config contains: ^\s*no cdp run" test_ref="oval:org.mitre.oval:tst:8904"/>
          </criteria>
          <criteria operator="AND">
            <criterion comment="config contains: cdp enable" test_ref="oval:org.mitre.oval:tst:8789"/>
            <criterion negate="true" comment="config contains: no cdp enable" test_ref="oval:org.mitre.oval:tst:8908"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5821" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Data-link Switching (DLSw) Unspecified DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1152" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1152"/>
        <description>The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:25.726-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:59.896-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:47.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2008-1152">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8729"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8735"/>
        <criterion comment="config contains: dlsw local-peer" test_ref="oval:org.mitre.oval:tst:8926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5820" version="1" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2254"/>
        <description>Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:52.988-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:09.720-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:32.748-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:582" version="1" class="vulnerability">
      <metadata>
        <title>MSJava Applet CODEBASE File Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Virtual Machine (VM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1258" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1258"/>
        <description>Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of msjava.dll is less than 5.0.3809.0" negate="false" test_ref="oval:org.mitre.oval:tst:2536"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5818" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0750" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0750"/>
        <description>Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a connection to TCP ports 3100-3999, 5100-5999, 7100-7999 and 10100-10999.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:26.030-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:59.677-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:47.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-0750">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8823"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8723"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5814" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running System Administration Manager (SAM), Unintended Remote Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1662"/>
        <description>Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote attackers to read or modify arbitrary files, related to an "empty systems list."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-31T12:40:22.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:31.251-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:09.394-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:32.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02286">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:8337"/>
            <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8776"/>
            <criterion comment="SystemAdmin.SAM is installed" test_ref="oval:org.mitre.oval:tst:8945"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_36562 is installed" test_ref="oval:org.mitre.oval:tst:8901"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02286">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:8337"/>
            <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8776"/>
            <criterion comment="SystemAdmin.SAM is installed" test_ref="oval:org.mitre.oval:tst:8945"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_36563 is installed" test_ref="oval:org.mitre.oval:tst:8924"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5813" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Systems IOS IPv6 Heap Corruption Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0195"/>
        <description>Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:26.334-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:59.463-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:47.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2005-0195">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8545"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8111"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5811" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398"/>
        <description>Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-30T13:13:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-07-02T17:04:30.472-04:00">DRAFT</status_change>
            <status_change date="2008-07-21T04:00:20.447-04:00">INTERIM</status_change>
            <status_change date="2008-08-11T04:00:44.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02341">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8191"/>
          <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8249"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7825"/>
          <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7691"/>
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7982"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:581" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="cdosys.dll is less than 6.5.6756.0" negate="false" test_ref="oval:org.mitre.oval:tst:2537"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5804" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Software Distributor Local Elevation of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5558"/>
        <description>Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument.  NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:32.634-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:41.781-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:36.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34814 is installed" test_ref="oval:org.mitre.oval:tst:8280"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SW-DIST.SD-CMDS version is less than B.11.23.0606.045" test_ref="oval:org.mitre.oval:tst:8496"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34539 is installed" test_ref="oval:org.mitre.oval:tst:8186"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34568 is installed" test_ref="oval:org.mitre.oval:tst:7611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5803" version="1" class="vulnerability">
      <metadata>
        <title>Cisco SSH Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1024"/>
        <description>Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:26.672-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:59.248-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:46.850-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2002-1024">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8886"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8714"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5802" version="0" class="vulnerability">
      <metadata>
        <title>PCX Plugin of Gimp Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1046"/>
        <description>Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-11T11:37:41.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:06.892-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:44.977-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-22 or later installed" test_ref="oval:org.mitre.oval:tst:8701"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 121775-01 or later installed" test_ref="oval:org.mitre.oval:tst:9219"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-22 or later installed" test_ref="oval:org.mitre.oval:tst:8353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5801" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Media Gateway Control Protocol Packet DoS Vulnerability and Facsimile
          Reception Overly Large Packet DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4293" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4293"/>
        <description>Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device crash) via (1) "abnormal" MGCP messages, aka CSCsd81407; and (2) a large facsimile packet, aka CSCej20505.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:26.900-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:58.758-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:46.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-4293">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8832"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8472"/>
        <criterion comment="config contains: service mgcpapp" test_ref="oval:org.mitre.oval:tst:8910"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:58" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS HTTP Redirect Error Message Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0075"/>
        <description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5797" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vendors SSH2 "null characters in strings" Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1360"/>
        <description>Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:27.069-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:58.475-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:45.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2002-1360">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8661"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8424"/>
        <criterion comment="config contains: crypto key generate rsa" test_ref="oval:org.mitre.oval:tst:8948"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5796" version="1" class="vulnerability">
      <metadata>
        <title>IBM AIX 'piox25.c/piox25remote.sh' Local Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>IBM AIX 4.3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0509"/>
        <description>Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:55.131-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:08.700-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:31.939-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <extend_definition comment="IBM AIX 4.3 is installed" definition_ref="oval:org.mitre.oval:def:4980"/>
        <criterion negate="true" comment="All filesets for APAR IZ13739 are installed" test_ref="oval:org.mitre.oval:tst:8896"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5790" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX newgrp(1), Local Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0379"/>
        <description>Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:35.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:33.169-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:41.563-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:36.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX00147">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8406"/>
        <criterion negate="true" comment="Patch PHCO_23083 is installed" test_ref="oval:org.mitre.oval:tst:8588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5789" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX libDtSvc, Local Increase in Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1764"/>
        <description>Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:34.781-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:41.181-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:35.499-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00308">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8474"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8492"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:7724"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8351"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7942"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8435"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8458"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_30167 is installed" test_ref="oval:org.mitre.oval:tst:8493"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00308">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8474"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7942"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:7724"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_28682 is installed" test_ref="oval:org.mitre.oval:tst:8526"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00308">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7942"/>
            <criterion comment="CDE.CDE-TCH-B-MSG is installed" test_ref="oval:org.mitre.oval:tst:8408"/>
            <criterion comment="CDE.CDE-ITA-I-MSG is installed" test_ref="oval:org.mitre.oval:tst:8256"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8474"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8435"/>
            <criterion comment="CDE.CDE-SCH-H-MSG is installed" test_ref="oval:org.mitre.oval:tst:8377"/>
            <criterion comment="CDE.CDE-SWE-I-MSG is installed" test_ref="oval:org.mitre.oval:tst:8580"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:7724"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8492"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_28676 is installed" test_ref="oval:org.mitre.oval:tst:8368"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00308">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8474"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8492"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:7724"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8351"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7942"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8435"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8458"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_28675 is installed" test_ref="oval:org.mitre.oval:tst:8507"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5788" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running shar(1), Local Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1099"/>
        <description>shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:35.478-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:40.872-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:35.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00304">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8504"/>
          <criterion negate="true" comment="Patch PHCO_2901 is installed" test_ref="oval:org.mitre.oval:tst:8574"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00304">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8504"/>
          <criterion negate="true" comment="Patch PHCO_29697 is installed" test_ref="oval:org.mitre.oval:tst:8309"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00304">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8504"/>
          <criterion negate="true" comment="Patch PHCO_28954 is installed" test_ref="oval:org.mitre.oval:tst:8532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5785" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vendors Net-SNMPv3 Hash Message Authentication Code Design Error
          Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0960" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0960"/>
        <description>SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; and (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:27.397-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:58.218-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:45.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2008-0960">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8885"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8684"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5784" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Express Forwarding Information Disclosure vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0339" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0339"/>
        <description>Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:27.691-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:58.001-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:44.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2002-0339">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8695"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8467"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5783" version="1" class="vulnerability">
      <metadata>
        <title>Buffer overflows in Software Distributor (SD) commands.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0688"/>
        <description>Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:17.742-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:40.631-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:34.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9907-101">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHCO_18183 is installed" test_ref="oval:org.mitre.oval:tst:8705"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5781" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS Session Initiation Protocol (SIP) Packet DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4292"/>
        <description>Multiple memory leaks in Cisco IOS 12.0 through 12.4 allow remote attackers to cause a denial of service (device crash) via a malformed SIP packet, aka (1) CSCsf11855, (2) CSCeb21064, (3) CSCse40276, (4) CSCse68355, (5) CSCsf30058, (6) CSCsb24007, and (7) CSCsc60249.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:27.837-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:57.796-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:44.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-4292">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8832"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8472"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:578" version="1">
      <metadata>
        <title>Microsoft Word Malformed Stack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference ref_id="CVE-2006-4534" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4534" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:48.722-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:59.701-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Word 2000" operator="AND">
          <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
          <criterion comment="the version of winword.exe is less than 9.0.0.8951" test_ref="oval:org.mitre.oval:tst:57"/>
        </criteria>
        <criteria comment="Word 2002" operator="AND">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of winword.exe is less than 10.0.6818.0" test_ref="oval:org.mitre.oval:tst:107"/>
        </criteria>
        <criteria comment="Word 2003" operator="AND">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of winword.exe is less than 11.0.8106.0" test_ref="oval:org.mitre.oval:tst:151"/>
        </criteria>
        <criteria comment="Word Viewer" operator="AND">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="the version of wordview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:28"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5779" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running logins(1M), Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5008"/>
        <description>The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:40.397-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:27.092-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:57.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36809 is installed" test_ref="oval:org.mitre.oval:tst:8204"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36003 is installed" test_ref="oval:org.mitre.oval:tst:8254"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36808 is installed" test_ref="oval:org.mitre.oval:tst:8264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5778" version="1" class="vulnerability">
      <metadata>
        <title>RSA BSAFE Cyrpt-C and Cert-C Libraries ASN.1 Object Parsing DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3894"/>
        <description>The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other products, allows remote attackers to cause a denial of service via malformed ASN.1 objects.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:28.393-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:57.201-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:43.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2006-3894">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8044"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8527"/>
        <criteria operator="OR">
          <criteria operator="AND">
            <criterion comment="config contains: ^\s*ip http secure-server" test_ref="oval:org.mitre.oval:tst:8767"/>
            <criterion negate="true" comment="config contains: ^\s*no ip http secure-server" test_ref="oval:org.mitre.oval:tst:8357"/>
          </criteria>
          <criterion comment="config contains: parameter-map type tms" test_ref="oval:org.mitre.oval:tst:8983"/>
          <criterion comment="config contains: crypto signaling default trustpoint" test_ref="oval:org.mitre.oval:tst:8848"/>
          <criterion comment="config contains: method tls" test_ref="oval:org.mitre.oval:tst:8967"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5775" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Ignite-UX, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0952" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0952"/>
        <description>HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:38.058-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:39.985-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:34.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01219">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Ignite-UX.BOOT-KRN-11-11 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8234"/>
            <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8284"/>
            <criterion comment="Ignite-UX.FILE-SRV-11-11 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8218"/>
            <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8436"/>
            <criterion comment="Ignite-UX.IGNITE version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7501"/>
            <criterion comment="Ignite-UX.OBAM-RUN version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8109"/>
            <criterion comment="Ignite-UX.RECOVERY version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8500"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01219">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Ignite-UX.BOOT-KRN-11-00 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8444"/>
            <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8284"/>
            <criterion comment="Ignite-UX.FILE-SRV-11-00 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8296"/>
            <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8436"/>
            <criterion comment="Ignite-UX.IGNITE version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7501"/>
            <criterion comment="Ignite-UX.OBAM-RUN version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8109"/>
            <criterion comment="Ignite-UX.RECOVERY version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8500"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01219">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Ignite-UX.BOOT-COMMON-IA version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8400"/>
            <criterion comment="Ignite-UX.BOOT-KRN-11-22 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8463"/>
            <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8284"/>
            <criterion comment="Ignite-UX.FILESRV-1122IA version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8487"/>
            <criterion comment="Ignite-UX.CFG-FILE-11-22 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7502"/>
            <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8436"/>
            <criterion comment="Ignite-UX.IGNITE version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7501"/>
            <criterion comment="Ignite-UX.OBAM-RUN version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8109"/>
            <criterion comment="Ignite-UX.RECOVERY version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8500"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01219">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Ignite-UX.BOOT-COMMON-IA version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8400"/>
            <criterion comment="Ignite-UX.BOOT-KRN-11-23 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8239"/>
            <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8284"/>
            <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8436"/>
            <criterion comment="Ignite-UX.IGNITE version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7501"/>
            <criterion comment="Ignite-UX.OBAM-RUN version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8109"/>
            <criterion comment="Ignite-UX.RECOVERY version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8500"/>
            <criterion comment="Ignite-UX.FILE-SRV-11-23 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8327"/>
            <criterion comment="Ignite-UX.BOOT-COMMON-PA version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7883"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5773" version="1" class="vulnerability">
      <metadata>
        <title>HP System Management Homepage (SMH) for HP-UX, Remote Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5302"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:39.840-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:26.590-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:56.797-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBMA02274">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          </criteria>
          <criterion comment="SysMgmtHomepage.SMH-RUN version is less than A.2.2.6.2" test_ref="oval:org.mitre.oval:tst:8169"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBMA02274">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criterion comment="SysMgmtHomepage.SMH-RUN is installed" test_ref="oval:org.mitre.oval:tst:7642"/>
          <criterion negate="true" comment="Patch PHSS_36871 is installed" test_ref="oval:org.mitre.oval:tst:8335"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBMA02274">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SysMgmtHomepage.SMH-RUN is installed" test_ref="oval:org.mitre.oval:tst:7642"/>
          <criterion negate="true" comment="Patch PHSS_36869 is installed" test_ref="oval:org.mitre.oval:tst:8094"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBMA02274">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SysMgmtHomepage.SMH-RUN is installed" test_ref="oval:org.mitre.oval:tst:7642"/>
          <criterion negate="true" comment="Patch PHSS_36870 is installed" test_ref="oval:org.mitre.oval:tst:8208"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5772" version="0" class="vulnerability">
      <metadata>
        <title>PSD Plugin of Gimp vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2949"/>
        <description>Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-11T11:37:41.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:07.128-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:44.579-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-22 or later installed" test_ref="oval:org.mitre.oval:tst:8701"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 121775-01 or later installed" test_ref="oval:org.mitre.oval:tst:9219"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-22 or later installed" test_ref="oval:org.mitre.oval:tst:8353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5770" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vendor OpenSSL 0.9.6x, 0.9.7x Null-Pointer DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:28.753-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:56.544-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:43.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2004-0079">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8567"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8785"/>
        <criterion comment="config contains: ^\s*ip http secure-server" test_ref="oval:org.mitre.oval:tst:8767"/>
        <criterion negate="true" comment="config contains: ^\s*no ip http secure-server" test_ref="oval:org.mitre.oval:tst:8357"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:577" version="2">
      <metadata>
        <title>Source Element Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3639" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when handling redirects, which allows remote attackers to read cross-domain web pages and possibly execute code via unspecified vectors involving a crafted web page, aka "Source Element Cross-Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:31.779-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.074-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:13.232-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:47.502-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5769" version="1" class="vulnerability">
      <metadata>
        <title>Cisco 12000 Series Internet Router Denial Of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0861" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0861"/>
        <description>Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:29.148-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:56.282-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:43.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-0861">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8513"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8756"/>
        <criterion negate="true" comment="config contains: no ip unreachables" test_ref="oval:org.mitre.oval:tst:8671"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5768" version="1" class="vulnerability">
      <metadata>
        <title>Memory Allocation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0120"/>
        <description>Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:00.590-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:07.155-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:31.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="PowerPoint 2000">
          <extend_definition comment="Microsoft PowerPoint 2000 is installed" definition_ref="oval:org.mitre.oval:def:696"/>
          <criterion comment="the version of powerpnt.exe is less than 9.0.0.8969" test_ref="oval:org.mitre.oval:tst:9017"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2002">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="the version of powerpnt.exe is less than 10.0.6842.0" test_ref="oval:org.mitre.oval:tst:8929"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2003">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="the version of powerpnt.exe is less than 11.0.8227.0" test_ref="oval:org.mitre.oval:tst:8173"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2007">
          <extend_definition comment="Microsoft PowerPoint 2007 is installed" definition_ref="oval:org.mitre.oval:def:5937"/>
          <criterion comment="the version of powerpnt.exe is less than 11.0.8227.0" test_ref="oval:org.mitre.oval:tst:8340"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint Viewer 2003">
          <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
          <criterion comment="the version of Pptview.exe is less than 11.0.8164.0" test_ref="oval:org.mitre.oval:tst:9044"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack 2007">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="the version of pptcnv.dll is less than 12.0.6320.5000" test_ref="oval:org.mitre.oval:tst:8980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5765" version="1" class="vulnerability">
      <metadata>
        <title>The Xserver was built incorrectly for HP-UX 11.22.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1098"/>
        <description>The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:38.764-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:39.717-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:34.065-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0301-238">
        <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
        <criterion negate="true" comment="Patch PHSS_25291 is installed" test_ref="oval:org.mitre.oval:tst:8261"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5763" version="1" class="vulnerability">
      <metadata>
        <title>An rlpdaemon logic flaw vulnerability has been reported to us that may allow a remote or local attacker to execute arbitrary code with superuser privilege.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1198"/>
        <description>RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:39.112-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:39.285-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:33.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0111-176">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion negate="true" comment="Patch PHCO_25110 is installed" test_ref="oval:org.mitre.oval:tst:8611"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0111-176">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion negate="true" comment="Patch PHCO_25111 is installed" test_ref="oval:org.mitre.oval:tst:8629"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5762" version="1" class="vulnerability">
      <metadata>
        <title>Vulnerability in the Solaris 10 Event Port Implementation May Lead to a System Panic, Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2706"/>
        <description>Unspecified vulnerability in the event port implementation in Sun Solaris 10 allows local users to cause a denial of service (panic) by submitting and retrieving user-defined events, probably related to a NULL dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-17T14:54:16.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-06-18T17:12:08.386-04:00">DRAFT</status_change>
            <status_change date="2008-07-07T04:00:36.344-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:26.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 235122">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-01 or later installed" test_ref="oval:org.mitre.oval:tst:7853"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 235122">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-01 or later installed" test_ref="oval:org.mitre.oval:tst:8065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5761" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND, Remote DNS Cache Poisoning</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447"/>
        <description>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-06T17:38:46.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-25T04:00:33.408-04:00">INTERIM</status_change>
            <status_change date="2008-09-15T04:00:25.507-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02351">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.3.0" test_ref="oval:org.mitre.oval:tst:8774"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02351">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-INETD is installed" test_ref="oval:org.mitre.oval:tst:8946"/>
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8959"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:9092"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_37865 is installed" test_ref="oval:org.mitre.oval:tst:8751"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02351">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.3.0" test_ref="oval:org.mitre.oval:tst:8774"/>
            <criterion comment="BindUpgrade.BIND2-UPGRADE version is less than C.9.3.2.3.0" test_ref="oval:org.mitre.oval:tst:7917"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02351">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.011" test_ref="oval:org.mitre.oval:tst:9077"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02351">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NameService.BIND-AUX version is less than C.9.3.2.3.0" test_ref="oval:org.mitre.oval:tst:8730"/>
            <criterion comment="NameService.BIND-RUN version is less than C.9.3.2.3.0" test_ref="oval:org.mitre.oval:tst:8646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5760" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running TCP/IP Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4316"/>
        <description>HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:39.974-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:37.771-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:33.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02087">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="Streams.STREAMS-KRN is installed" test_ref="oval:org.mitre.oval:tst:8347"/>
          <criterion negate="true" comment="Patch PHNE_34131 is installed" test_ref="oval:org.mitre.oval:tst:8382"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02087">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8422"/>
          <criterion negate="true" comment="Patch PHNE_33427 is installed" test_ref="oval:org.mitre.oval:tst:8100"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02087">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="Streams.STREAMS-KRN is installed" test_ref="oval:org.mitre.oval:tst:8347"/>
          <criterion negate="true" comment="Patch PHNE_30161 is installed" test_ref="oval:org.mitre.oval:tst:8396"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02087">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="Streams.STREAMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8262"/>
          <criterion negate="true" comment="Patch PHKL_31500 is installed" test_ref="oval:org.mitre.oval:tst:8386"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:576" version="1" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2539"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5759" version="1" class="vulnerability">
      <metadata>
        <title>VMware ESX Openwsman Lets Local Users Gain Root Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2097"/>
        <description>Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote authenticated users to gain privileges via an "invalid Content-Length."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-06-16T18:09:19.449-04:00">DRAFT</status_change>
            <status_change date="2008-07-07T04:00:35.475-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:25.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="VMWare ESX Server 3.0.2 meets CVE-2008-2097">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5529"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1004727 is not installed" test_ref="oval:org.mitre.oval:tst:8164"/>
            <criterion comment="Patch ESX-1004821 is not installed" test_ref="oval:org.mitre.oval:tst:8020"/>
            <criterion comment="Patch ESX-1004216 is not installed" test_ref="oval:org.mitre.oval:tst:8154"/>
            <criterion comment="Patch ESX-1004726 is not installed" test_ref="oval:org.mitre.oval:tst:7728"/>
            <criterion comment="Patch ESX-1004722 is not installed" test_ref="oval:org.mitre.oval:tst:7216"/>
            <criterion comment="Patch ESX-1004724 is not installed" test_ref="oval:org.mitre.oval:tst:8179"/>
            <criterion comment="Patch ESX-1004719 is not installed" test_ref="oval:org.mitre.oval:tst:7839"/>
            <criterion comment="Patch ESX-1004219 is not installed" test_ref="oval:org.mitre.oval:tst:8155"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="VMWare ESX Server 3.0.1 meets CVE-2008-2097">
          <extend_definition comment="VMWare ESX Server 3.0.1 is installed" definition_ref="oval:org.mitre.oval:def:5367"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1004186 is not installed" test_ref="oval:org.mitre.oval:tst:8017"/>
            <criterion comment="Patch ESX-1004728 is not installed" test_ref="oval:org.mitre.oval:tst:7956"/>
            <criterion comment="Patch ESX-1004725 is not installed" test_ref="oval:org.mitre.oval:tst:8178"/>
            <criterion comment="Patch ESX-1004721 is not installed" test_ref="oval:org.mitre.oval:tst:8143"/>
            <criterion comment="Patch ESX-1004723 is not installed" test_ref="oval:org.mitre.oval:tst:8153"/>
            <criterion comment="Patch ESX-1004190 is not installed" test_ref="oval:org.mitre.oval:tst:7941"/>
            <criterion comment="Patch ESX-1004189 is not installed" test_ref="oval:org.mitre.oval:tst:7964"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="VMWare ESX Server 2.5.5 meets CVE-2008-2097">
          <criterion comment="VMWare ESX Server 2.5.5 build 57619 or higher is installed" test_ref="oval:org.mitre.oval:tst:8174"/>
          <criterion comment="VMWare ESX Server 2.5.5 upgrade patch 8 is not installed" test_ref="oval:org.mitre.oval:tst:7900"/>
        </criteria>
        <criteria operator="AND" comment="VMWare ESX Server 2.5.4 meets CVE-2008-2097">
          <criterion comment="VMWare ESX Server 2.5.4 build 32233 or higher is installed" test_ref="oval:org.mitre.oval:tst:7750"/>
          <criterion comment="VMWare ESX Server 2.5.4 upgrade patch 19 is not installed" test_ref="oval:org.mitre.oval:tst:8124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5758" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running sort, Remote Unauthorized Access, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1356"/>
        <description>The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:40.640-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:37.429-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:32.634-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00237">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_28467 is installed" test_ref="oval:org.mitre.oval:tst:8407"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00237">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_25918 is installed" test_ref="oval:org.mitre.oval:tst:7899"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00237">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_27565 is installed" test_ref="oval:org.mitre.oval:tst:8209"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5756" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS RADIUS Authentication Bypass Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2105"/>
        <description>Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:29.793-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:55.981-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:42.538-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2005-2105">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8860"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8538"/>
        <criteria operator="OR">
          <criterion comment="config contains: aaa authentication login \S+ group radius none" test_ref="oval:org.mitre.oval:tst:8909"/>
          <criterion comment="config contains: aaa authentication ppp \S+ group radius none" test_ref="oval:org.mitre.oval:tst:8410"/>
          <criterion comment="config contains: aaa authentication login \S+ group radius local none" test_ref="oval:org.mitre.oval:tst:9081"/>
          <criterion comment="config contains: aaa authentication ppp \S+ group radius local none" test_ref="oval:org.mitre.oval:tst:9040"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5754" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS 12.0 Security Policy Circumvention Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0867" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0867"/>
        <description>Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:30.151-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:55.753-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:42.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-0867">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8800"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8750"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5752" version="1" class="vulnerability">
      <metadata>
        <title>The SharedX program recserv is vulnerable to a denial of service attack.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0779"/>
        <description>Denial of service in HP-UX SharedX recserv program.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:18.615-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:37.217-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:32.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9810-086">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_16649 is installed" test_ref="oval:org.mitre.oval:tst:8765"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:575" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Workstation Service Logging Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Windows Workstation Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0812"/>
        <description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of wkssvc.dll is less than 5.00.2195.6862" negate="false" test_ref="oval:org.mitre.oval:tst:2541"/>
          <criterion comment="the patch q828748 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2540"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the workstation service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5747" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running X.25 Local Denial of Service (Dos)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4820"/>
        <description>Unspecified vulnerability in X.25 on HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:35.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02126" date="2008-07-14T10:21:00.896-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-08-04T04:00:36.637-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:31.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02126">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SX25-HPerf.SX25-HPERF-COM is installed" test_ref="oval:org.mitre.oval:tst:8693"/>
            <criterion comment="SX25-HPerf.COM-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8654"/>
            <criterion comment="SX25-HPerf.IP-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8350"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PAD is installed" test_ref="oval:org.mitre.oval:tst:7703"/>
            <criterion comment="SYNC-WAN.SYNC-ALIB is installed" test_ref="oval:org.mitre.oval:tst:7910"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_34999 is installed" test_ref="oval:org.mitre.oval:tst:8700"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02126">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SX25-HPerf.SX25-HPERF-IP is installed" test_ref="oval:org.mitre.oval:tst:8433"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PA is installed" test_ref="oval:org.mitre.oval:tst:8126"/>
            <criterion comment="SX25-HPerf.COM-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8235"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-SAM is installed" test_ref="oval:org.mitre.oval:tst:8648"/>
            <criterion comment="SYNC-WAN.SYNC-ALIB is installed" test_ref="oval:org.mitre.oval:tst:7910"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PAD is installed" test_ref="oval:org.mitre.oval:tst:7703"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-COM is installed" test_ref="oval:org.mitre.oval:tst:8693"/>
            <criterion comment="SX25-HPerf.PA-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8683"/>
            <criterion comment="SX25-HPerf.COM-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8654"/>
            <criterion comment="SYNC-WAN.SYNC-COM is installed" test_ref="oval:org.mitre.oval:tst:8190"/>
            <criterion comment="SX25-HPerf.SX25-SNMP is installed" test_ref="oval:org.mitre.oval:tst:8689"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-MAN is installed" test_ref="oval:org.mitre.oval:tst:7710"/>
            <criterion comment="SX25-HPerf.IP-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8350"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_34988 is installed" test_ref="oval:org.mitre.oval:tst:8448"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02126">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SX25-HPerf.SX25-SNMP is installed" test_ref="oval:org.mitre.oval:tst:8689"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-MAN is installed" test_ref="oval:org.mitre.oval:tst:7710"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PA is installed" test_ref="oval:org.mitre.oval:tst:8126"/>
            <criterion comment="SYNC-WAN.SYNC-32ALIB is installed" test_ref="oval:org.mitre.oval:tst:8483"/>
            <criterion comment="SYNC-WAN.SYNC-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8146"/>
            <criterion comment="SX25-HPerf.COM-32ALIB is installed" test_ref="oval:org.mitre.oval:tst:8645"/>
            <criterion comment="SYNC-WAN.SYNC-COM is installed" test_ref="oval:org.mitre.oval:tst:8190"/>
            <criterion comment="SX25-HPerf.COM-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8678"/>
            <criterion comment="SX25-HPerf.IP-32ALIB is installed" test_ref="oval:org.mitre.oval:tst:8619"/>
            <criterion comment="SX25-HPerf.IP-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8669"/>
            <criterion comment="SX25-HPerf.PA-32ALIB is installed" test_ref="oval:org.mitre.oval:tst:8522"/>
            <criterion comment="SX25-HPerf.PA-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8192"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PAD is installed" test_ref="oval:org.mitre.oval:tst:7703"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-COM is installed" test_ref="oval:org.mitre.oval:tst:8693"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-IP is installed" test_ref="oval:org.mitre.oval:tst:8433"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-SAM is installed" test_ref="oval:org.mitre.oval:tst:8648"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_34009 is installed" test_ref="oval:org.mitre.oval:tst:8621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5746" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Kernel Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3201"/>
        <description>Unspecified vulnerability in the kernel in HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:43.427-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:36.260-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:31.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02127">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34193 is installed" test_ref="oval:org.mitre.oval:tst:8306"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02127">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34192 is installed" test_ref="oval:org.mitre.oval:tst:8418"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02127">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34194 is installed" test_ref="oval:org.mitre.oval:tst:8384"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5745" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS SSL ChamgeCipherSpec DoS Vulnerability, ClientHello DoS Vulnerability and
          Finished Message DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2813"/>
        <description>Cisco IOS 12.4 and earlier, when using the crypto packages and SSL support is enabled, allows remote attackers to cause a denial of service via a malformed (1) ClientHello, (2) ChangeCipherSpec, or (3) Finished message during an SSL session.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:30.561-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:55.493-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:41.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-2813">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8866"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8625"/>
        <criteria operator="OR">
          <criterion comment="config contains: cns config \S+ \S+ encrypt" test_ref="oval:org.mitre.oval:tst:8989"/>
          <criteria operator="AND">
            <criterion comment="config contains: ^\s*ip http secure-server" test_ref="oval:org.mitre.oval:tst:8767"/>
            <criterion negate="true" comment="config contains: ^\s*no ip http secure-server" test_ref="oval:org.mitre.oval:tst:8357"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5744" version="1" class="vulnerability">
      <metadata>
        <title>AIX swap commands buffer overflow</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0584" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0584"/>
        <description>Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-18T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-08T13:06:05.709-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:25.093-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:55.143-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2008-0584">
          <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
          <criterion negate="true" comment="All filesets for APAR IY96095 are installed" test_ref="oval:org.mitre.oval:tst:8170"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-06 meets CVE-2008-0584">
          <extend_definition comment="IBM AIX 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:4813"/>
          <criterion negate="true" comment="All filesets for APAR IY96101 are installed" test_ref="oval:org.mitre.oval:tst:8391"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2008-0584">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IY95874 are installed" test_ref="oval:org.mitre.oval:tst:8233"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5743" version="1" class="vulnerability">
      <metadata>
        <title>A TCP SYN packet with target host's address as both source and destination can cause system hangs.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0104"/>
        <description>A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:19.052-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:36.058-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:31.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9801-076">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_14017 is installed" test_ref="oval:org.mitre.oval:tst:8302"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5742" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0965"/>
        <description>Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T12:08:06.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:06.340-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:05.820-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:30.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138083-01 or later installed" test_ref="oval:org.mitre.oval:tst:9062"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112915-05 or later installed" test_ref="oval:org.mitre.oval:tst:9103"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 108964-11 or later installed" test_ref="oval:org.mitre.oval:tst:8936"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138084-01 or later installed" test_ref="oval:org.mitre.oval:tst:8152"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114262-04 or later installed" test_ref="oval:org.mitre.oval:tst:8854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 108965-11 or later installed" test_ref="oval:org.mitre.oval:tst:9126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5741" version="1" class="vulnerability">
      <metadata>
        <title>Cisco "EIGRP" Protocol "HELLO" Packet Replay Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4437" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4437"/>
        <description>MD5 Neighbor Authentication in Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS 11.3 and later, does not include the Message Authentication Code (MAC) in the checksum, which allows remote attackers to sniff message hashes and (1) replay EIGRP HELLO messages or (2) cause a denial of service by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:30.907-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:54.898-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:41.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2005-4437">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8536"/>
        <criterion comment="config contains: router eigrp" test_ref="oval:org.mitre.oval:tst:8871"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5740" version="5" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T02:20:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:31.382-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:58.311-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:47.041-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.853-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:53:30.233-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:19.716-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5738" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Systems IOS Unauthorized IPSec SA Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1058"/>
        <description>Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:31.084-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:54.461-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:40.957-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2005-1058">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8755"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8721"/>
        <criteria operator="OR">
          <criterion comment="config contains: crypto map \S+ client authentication list" test_ref="oval:org.mitre.oval:tst:8976"/>
          <criteria operator="AND">
            <criterion comment="config contains: crypto isakmp profile" test_ref="oval:org.mitre.oval:tst:9110"/>
            <criterion comment="config contains: crypto isakmp profile" test_ref="oval:org.mitre.oval:tst:9110"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5735" version="1" class="vulnerability">
      <metadata>
        <title>The NSAPI plugin versions of the TGA and the Java Servlet proxy demonstrate high CPU utilization under certain conditions.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0965"/>
        <description>The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:15.467-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:35.742-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:30.960-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0010-124">
        <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
        <criterion negate="true" comment="Patch PHSS_22296 is installed" test_ref="oval:org.mitre.oval:tst:8633"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5734" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running rpc.yppasswdd, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6419" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6419"/>
        <description>Unspecified vulnerability in rpc.yppasswdd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:37.367-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:24.521-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:53.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02295">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NFS.NISPLUS-CORE is installed" test_ref="oval:org.mitre.oval:tst:7923"/>
            <criterion comment="NFS.NFS-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8171"/>
            <criterion comment="NFS.NIS-CLIENT is installed" test_ref="oval:org.mitre.oval:tst:8102"/>
            <criterion comment="OS-Core.CORE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:7936"/>
            <criterion comment="NFS.NFS-KRN is installed" test_ref="oval:org.mitre.oval:tst:8257"/>
            <criterion comment="NFS.KEY-CORE is installed" test_ref="oval:org.mitre.oval:tst:7850"/>
            <criterion comment="NFS.NFS-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8231"/>
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8172"/>
            <criterion comment="NFS.NFS-CLIENT is installed" test_ref="oval:org.mitre.oval:tst:7618"/>
            <criterion comment="NFS.NFS-CORE is installed" test_ref="oval:org.mitre.oval:tst:8269"/>
            <criterion comment="NFS.NFS-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8228"/>
            <criterion comment="NFS.NIS-CORE is installed" test_ref="oval:org.mitre.oval:tst:8263"/>
            <criterion comment="NFS.NFS-PRG is installed" test_ref="oval:org.mitre.oval:tst:8026"/>
            <criterion comment="NFS.NFS-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8240"/>
            <criterion comment="NFS.NIS-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8130"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_36168 is installed" test_ref="oval:org.mitre.oval:tst:7312"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02295">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criterion comment="NFS.NIS2-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8304"/>
          <criterion negate="true" comment="Patch PHNE_36449 is installed" test_ref="oval:org.mitre.oval:tst:8160"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02295">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8172"/>
            <criterion comment="NFS.NIS2-CLIENT is installed" test_ref="oval:org.mitre.oval:tst:7323"/>
            <criterion comment="NFS.NFS-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8228"/>
            <criterion comment="NFS.NISPLUS-CORE is installed" test_ref="oval:org.mitre.oval:tst:7923"/>
            <criterion comment="NFS.KEY-CORE is installed" test_ref="oval:org.mitre.oval:tst:7850"/>
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8172"/>
            <criterion comment="NFS.NIS2-CLIENT is installed" test_ref="oval:org.mitre.oval:tst:7323"/>
            <criterion comment="NFS.NIS2-CORE is installed" test_ref="oval:org.mitre.oval:tst:8316"/>
            <criterion comment="NFS.NIS2-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8304"/>
            <criterion comment="NFS.NIS2-CORE is installed" test_ref="oval:org.mitre.oval:tst:8316"/>
            <criterion comment="NFS.KEY-CORE is installed" test_ref="oval:org.mitre.oval:tst:7850"/>
            <criterion comment="NFS.NIS2-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8304"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_36260 is installed" test_ref="oval:org.mitre.oval:tst:7570"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5733" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105"/>
        <description>Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-30T13:13:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-07-02T17:04:30.957-04:00">DRAFT</status_change>
            <status_change date="2008-07-21T04:00:20.151-04:00">INTERIM</status_change>
            <status_change date="2008-08-11T04:00:42.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02341">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8191"/>
          <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8249"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7825"/>
          <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7691"/>
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7982"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5731" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in IP Multicast Filter processing of Sockets may lead to a system panic or possible execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2710"/>
        <description>Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory.  NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-17T14:54:16.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-06-18T17:12:08.608-04:00">DRAFT</status_change>
            <status_change date="2008-07-07T04:00:34.971-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:24.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237965">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-01 or later installed" test_ref="oval:org.mitre.oval:tst:7853"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237965">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-01 or later installed" test_ref="oval:org.mitre.oval:tst:8065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5730" version="1" class="vulnerability">
      <metadata>
        <title>The lpspool subsystem has various security oriented defects.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0966" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0966"/>
        <description>Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:15.206-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:35.403-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:30.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0010-125">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHCO_22365 is installed" test_ref="oval:org.mitre.oval:tst:8486"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:573" version="1" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (32-bit XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.2900.2620" negate="false" test_ref="oval:org.mitre.oval:tst:2543"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2542"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5729" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vendor SSH 1.5 Session Key Recovery Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0361" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0361"/>
        <description>Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:31.427-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:53.180-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:40.338-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-0361">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8889"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5728" version="1" class="vulnerability">
      <metadata>
        <title>/opt/audio/bin/Aserver can be used to gain root access.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0078"/>
        <description>The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:16.740-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:35.146-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:30.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0001-108">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_21663 is installed" test_ref="oval:org.mitre.oval:tst:8307"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5727" version="1" class="vulnerability">
      <metadata>
        <title>A TCP SYN packet with target host's address as both source and destination can cause system hangs.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0016"/>
        <description>Land IP denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:19.348-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:34.904-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:30.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9801-076">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_14017 is installed" test_ref="oval:org.mitre.oval:tst:8302"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5725" version="1" class="vulnerability">
      <metadata>
        <title>DNS Insufficient Socket Entropy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447"/>
        <description>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T14:18:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-07-11T10:55:58.695-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:23.732-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:52.726-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="dnsapi.dll version is less than 5.0.2195.7158" test_ref="oval:org.mitre.oval:tst:8348"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="dnsapi.dll version is less than 5.1.2600.3394" test_ref="oval:org.mitre.oval:tst:8137"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="dnsapi.dll version is less than 5.1.2600.5625" test_ref="oval:org.mitre.oval:tst:8530"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <criterion comment="dnsapi.dll version is less than 5.2.3790.3161" test_ref="oval:org.mitre.oval:tst:8185"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="dnsapi.dll version is less than 5.2.3790.4318" test_ref="oval:org.mitre.oval:tst:8047"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="dnsapi.dll version is less than 5.2.3790.3161" test_ref="oval:org.mitre.oval:tst:8185"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="dnsapi.dll version is less than 5.2.3790.4318" test_ref="oval:org.mitre.oval:tst:8047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5724" version="1" class="vulnerability">
      <metadata>
        <title>Memory Calculation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0121"/>
        <description>A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:06.907-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:04.633-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:29.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="PowerPoint 2000">
          <extend_definition comment="Microsoft PowerPoint 2000 is installed" definition_ref="oval:org.mitre.oval:def:696"/>
          <criterion comment="the version of powerpnt.exe is less than 9.0.0.8969" test_ref="oval:org.mitre.oval:tst:9017"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2002">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="the version of powerpnt.exe is less than 10.0.6842.0" test_ref="oval:org.mitre.oval:tst:8929"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2003">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="the version of powerpnt.exe is less than 11.0.8227.0" test_ref="oval:org.mitre.oval:tst:8173"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2007">
          <extend_definition comment="Microsoft PowerPoint 2007 is installed" definition_ref="oval:org.mitre.oval:def:5937"/>
          <criterion comment="the version of powerpnt.exe is less than 11.0.8227.0" test_ref="oval:org.mitre.oval:tst:8340"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint Viewer 2003">
          <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
          <criterion comment="the version of Pptview.exe is less than 11.0.8164.0" test_ref="oval:org.mitre.oval:tst:9044"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack 2007">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="the version of pptcnv.dll is less than 12.0.6320.5000" test_ref="oval:org.mitre.oval:tst:8980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5721" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vendors SSH2 "lists with empty elements or multiple separators"
          Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1358" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1358"/>
        <description>Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:31.562-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:52.466-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:40.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2002-1358">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8661"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8424"/>
        <criterion comment="config contains: crypto key generate rsa" test_ref="oval:org.mitre.oval:tst:8948"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5720" version="1" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1442"/>
        <description>Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code, related to an unspecified manipulation of a DOM object before a call to this method, aka the "HTML Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T14:50:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:49.284-04:00">DRAFT</status_change>
            <status_change date="2008-06-30T04:00:18.670-04:00">INTERIM</status_change>
            <status_change date="2008-07-21T04:00:19.533-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1611" test_ref="oval:org.mitre.oval:tst:8059"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          </criteria>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3354" test_ref="oval:org.mitre.oval:tst:8055"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16674" test_ref="oval:org.mitre.oval:tst:7361"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3123" test_ref="oval:org.mitre.oval:tst:7949"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4275" test_ref="oval:org.mitre.oval:tst:7988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16674" test_ref="oval:org.mitre.oval:tst:7361"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3123" test_ref="oval:org.mitre.oval:tst:7949"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4275" test_ref="oval:org.mitre.oval:tst:7988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16674" test_ref="oval:org.mitre.oval:tst:7361"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3123" test_ref="oval:org.mitre.oval:tst:7949"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4275" test_ref="oval:org.mitre.oval:tst:7988"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16681" test_ref="oval:org.mitre.oval:tst:8012"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18063" test_ref="oval:org.mitre.oval:tst:8066"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18063" test_ref="oval:org.mitre.oval:tst:8066"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:572" version="2" class="vulnerability">
      <metadata>
        <title>Sendmail BO in Prescan Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:38.145-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:36.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-5.90" negate="false" test_ref="oval:org.mitre.oval:tst:2549"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5718" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS ILMI SNMP Community String Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0380"/>
        <description>Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-02T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:31.847-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:52.240-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:39.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2001-0380">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8851"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8481"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5714" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS 12.4 Malformed DLSw Message DoS Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0199"/>
        <description>The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:32.201-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:51.981-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:39.103-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2007-0199">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8853"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8809"/>
        <criterion comment="config contains: dlsw local-peer" test_ref="oval:org.mitre.oval:tst:8973"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5713" version="1" class="vulnerability">
      <metadata>
        <title>Cisco IOS GRE Source Routing Integer Overflow ACL Bypass Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4650" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4650"/>
        <description>Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:32.446-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:51.734-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:38.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2006-4650">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8798"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5711" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Systems Spoofed TCP Reset and SYN Denial of Service Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0230"/>
        <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:32.716-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:51.474-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:38.111-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2004-0230">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8766"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8552"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5710" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running DCE, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6195"/>
        <description>Buffer overflow in the sw_rpc_agent_init function in swagentd in Software Distributor (SD), and possibly other DCE applications, in HP HP-UX B.11.11 and B.11.23 allows remote attackers to execute arbitrary code or cause a denial of service via malformed arguments in an opcode 0x04 DCE RPC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:38.573-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:23.352-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:51.007-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02294">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="DCE-Core.DCEC-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:7422"/>
            <criterion comment="DCE-Core.DCE-CORE-DTS is installed" test_ref="oval:org.mitre.oval:tst:7983"/>
            <criterion comment="DCE-Core.DCE-CORE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8210"/>
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:7341"/>
            <criterion comment="DCE-Core.DCE-COR-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8194"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_36004 is installed" test_ref="oval:org.mitre.oval:tst:8328"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02294">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="DCE-CoreTools.DCE-BPRG is installed" test_ref="oval:org.mitre.oval:tst:8087"/>
            <criterion comment="DCE-Core.DCE-CORE-DTS is installed" test_ref="oval:org.mitre.oval:tst:7983"/>
            <criterion comment="DCE-Core.DCE-CORE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8210"/>
            <criterion comment="DCE-Core.DCE-COR-PA-RUN is installed" test_ref="oval:org.mitre.oval:tst:8214"/>
            <criterion comment="DCE-Core.DCE-COR-IA-RUN is installed" test_ref="oval:org.mitre.oval:tst:8223"/>
            <criterion comment="DCE-Core.DCE-COR-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8194"/>
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:7341"/>
            <criterion comment="DCE-Core.DCE-IA64-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:8286"/>
            <criterion comment="DCE-Core.DCEC-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:7422"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_36005 is installed" test_ref="oval:org.mitre.oval:tst:8134"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5709" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ftpd Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2993"/>
        <description>Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:51.032-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:34.272-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:29.875-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.00.01.005" test_ref="oval:org.mitre.oval:tst:7619"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_34077 is installed" test_ref="oval:org.mitre.oval:tst:7658"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.11.01.006" test_ref="oval:org.mitre.oval:tst:8501"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8367"/>
          <criterion negate="true" comment="Patch PHNE_33414 is installed" test_ref="oval:org.mitre.oval:tst:8565"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_33412 is installed" test_ref="oval:org.mitre.oval:tst:8556"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_33406 is installed" test_ref="oval:org.mitre.oval:tst:8502"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5704" version="1" class="vulnerability">
      <metadata>
        <title>AIX Logical Volume Manager buffer overflow</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0586"/>
        <description>Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm; and the (6) tellclvmd program in bos.clvm.enh.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-18T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-08T13:06:05.115-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:22.930-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:50.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5.2 meets CVE-2008-0586">
          <extend_definition comment="IBM AIX 5.2 is installed" definition_ref="oval:org.mitre.oval:def:5189"/>
          <criteria operator="OR">
            <criterion negate="true" comment="All filesets for APAR IZ10828 are installed" test_ref="oval:org.mitre.oval:tst:7860"/>
            <criterion negate="true" comment="All filesets for APAR IZ00559 are installed" test_ref="oval:org.mitre.oval:tst:8285"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-06 meets CVE-2008-0586">
          <extend_definition comment="IBM AIX 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:4813"/>
          <criteria operator="OR">
            <criterion negate="true" comment="All filesets for APAR IY99537 are installed" test_ref="oval:org.mitre.oval:tst:8308"/>
            <criterion negate="true" comment="All filesets for APAR IY98340 are installed" test_ref="oval:org.mitre.oval:tst:8431"/>
            <criterion negate="true" comment="All filesets for APAR IY98331 are installed" test_ref="oval:org.mitre.oval:tst:8070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2008-0586">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criteria operator="OR">
            <criterion negate="true" comment="All filesets for APAR IY99517 are installed" test_ref="oval:org.mitre.oval:tst:8420"/>
            <criterion negate="true" comment="All filesets for APAR IY98450 are installed" test_ref="oval:org.mitre.oval:tst:8268"/>
            <criterion negate="true" comment="All filesets for APAR IY98448 are installed" test_ref="oval:org.mitre.oval:tst:8412"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5702" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2551"/>
        <description>Unspecified vulnerability in the kernel in HP-UX B.11.00 allows local users to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:51.534-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:33.911-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:29.589-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02120">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34940 is installed" test_ref="oval:org.mitre.oval:tst:8324"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02120">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34406 is installed" test_ref="oval:org.mitre.oval:tst:8359"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5701" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd, Remote Privileged Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1332" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1332"/>
        <description>Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:52.234-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:33.540-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:29.191-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.00.01.003" test_ref="oval:org.mitre.oval:tst:8499"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_31034 is installed" test_ref="oval:org.mitre.oval:tst:8485"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.11.01.003" test_ref="oval:org.mitre.oval:tst:8411"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_29461 is installed" test_ref="oval:org.mitre.oval:tst:8461"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8367"/>
          <criterion negate="true" comment="Patch PHNE_29462 is installed" test_ref="oval:org.mitre.oval:tst:8342"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_29460 is installed" test_ref="oval:org.mitre.oval:tst:8395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5700" version="1" class="vulnerability">
      <metadata>
        <title>OnLineJFS sticky bit does not function properly.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1618" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1618"/>
        <description>JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:52.820-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:33.081-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:28.948-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0210-223">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHKL_24201 is installed" test_ref="oval:org.mitre.oval:tst:7939"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:570" version="1">
      <metadata>
        <title>Excel Malformed DATETIME Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-2387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2387" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:48.120-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:58.954-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8950" test_ref="oval:org.mitre.oval:tst:35"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6816.0" test_ref="oval:org.mitre.oval:tst:173"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8105.0" test_ref="oval:org.mitre.oval:tst:26"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:27"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:57" version="1" class="vulnerability">
      <metadata>
        <title>Improper Cross Domain Security Validation with ShowHelp Functionality</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1328" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1328"/>
        <description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2723.2500" negate="false" test_ref="oval:org.mitre.oval:tst:3003"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5696" version="1" class="vulnerability">
      <metadata>
        <title>Cisco Systems IPSec VPN Services Module Malformed IKE Packet Vulnerability</title>
        <affected family="ios">
          <platform>Cisco IOS</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0710"/>
        <description>IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (device crash and reload) via a malformed Internet Key Exchange (IKE) packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-07-30T16:33:32.974-04:00">DRAFT</status_change>
            <status_change date="2008-08-18T04:00:50.330-04:00">INTERIM</status_change>
            <status_change date="2008-09-08T04:00:37.350-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco ISO meets CVE-2004-0710">
        <criterion comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8569"/>
        <criterion negate="true" comment="IOS vulnerable versions" test_ref="oval:org.mitre.oval:tst:8647"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5695" version="1" class="vulnerability">
      <metadata>
        <title>OWA For Exchange Server Parsing XSS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2248"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T14:18:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-07-11T10:55:59.238-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:22.634-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:49.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2007 (no Service Pack) is installed" definition_ref="oval:org.mitre.oval:def:1641"/>
          <criterion comment="cdoex.dll is less than 8.0.813.0" test_ref="oval:org.mitre.oval:tst:8570"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2007 SP1 is installed" definition_ref="oval:org.mitre.oval:def:5577"/>
          <criterion comment="cdoex.dll is less than 8.1.291.1" test_ref="oval:org.mitre.oval:tst:8531"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5694" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ARPA Transport, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2665" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2665"/>
        <description>Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.00, B.11.04, and B.11.11 before 20040628 allows local users to cause a denial of service via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:57.129-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:32.725-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:28.595-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01054">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8422"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8288"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8224"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8289"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_29887 is installed" test_ref="oval:org.mitre.oval:tst:7915"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01054">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8422"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8288"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8224"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8289"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_30905 is installed" test_ref="oval:org.mitre.oval:tst:8438"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01054">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8422"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8288"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8224"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8289"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_29473 is installed" test_ref="oval:org.mitre.oval:tst:7722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5691" version="1" class="inventory">
      <metadata>
        <title>Windows Messenger 5.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office:2000"/>
        <description>The application Windows Messenger 5.1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:34.047-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:03.898-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:28.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Messenger 5.1 is installed" test_ref="oval:org.mitre.oval:tst:9121"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5690" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND v9.2.0, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0364"/>
        <description>Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:58.162-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:32.403-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:28.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01117">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.006" test_ref="oval:org.mitre.oval:tst:8068"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01117">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8005"/>
          <criterion negate="true" comment="Patch PHNE_32783 is installed" test_ref="oval:org.mitre.oval:tst:8354"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01117">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.00.01.004" test_ref="oval:org.mitre.oval:tst:84
