<?xml version="1.0" encoding="UTF-8"?>
<oval xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns:redhat="http://oval.mitre.org/XMLSchema/oval#redhat" xmlns:solaris="http://oval.mitre.org/XMLSchema/oval#solaris" xmlns:windows="http://oval.mitre.org/XMLSchema/oval#windows" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval oval-schema.xsd http://oval.mitre.org/XMLSchema/oval#redhat redhat-schema.xsd http://oval.mitre.org/XMLSchema/oval#solaris solaris-schema.xsd http://oval.mitre.org/XMLSchema/oval#windows windows-schema.xsd" oval:schemaVersion="3.0" windows:schemaVersion="3.0" redhat:schemaVersion="3.0" solaris:schemaVersion="3.0" oval:timeStamp="20050112134741">
	<definitions>
		<definition id="OVAL2" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mutt</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0140</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-201" comment="balsa version is less than 2.0.6-2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-201" comment="/usr/bin/balsa is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>CUPS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0195</cveid>
			<dates>
				<created date="2003-08-19"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-202" comment="cups version is less than 1.1.17-13.3" />
				</software>
				<configuration>
					<criterion test_ref="rlt-201" comment="cupsd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>kcms_configure</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0594</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-201" comment="File kcms_configure exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL9" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>libnsl</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0391</cveid>
			<dates>
				<created date="2003-01-28"/>
			</dates>
			<description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" />
					<criterion test_ref="cmp-205" negate="true" comment="Patches 108827-30 and 108901-06" />
				</software>
				<configuration>
					<criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL10" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>xlock</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0652</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-204" comment="File xlock exists" />
					<criterion test_ref="spt-203" negate="true" comment="Patch 108652-38 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-209" comment="File xlock SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL11" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>snmpdx</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0796</cveid>
			<dates>
				<created date="2002-09-25"/>
			</dates>
			<description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-205" comment="File snmpdx exists" />
					<criterion test_ref="spt-204" negate="true" comment="Patch 108869-16 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-203" comment="snmpdx running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL12" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0026</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL14" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Xsun</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0158</cveid>
			<dates>
				<created date="2002-08-23"/>
			</dates>
			<description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-206" comment="File Xsun exists" />
					<criterion test_ref="spt-205" negate="true" comment="Patch 108652-52 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-210" comment="File Xsun SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL15" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0677</cveid>
			<dates>
				<created date="2003-01-31"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-206" negate="true" comment="Patch 110286-09 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL16" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0079</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL17" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0023</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL18" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CVE">2002-0070</cveid>
			<dates>
				<created date="2004-09-15"/>
				<modified date="2004-09-16">Completing an initial submission.</modified>
				<modified date="2004-10-19">done</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-13">INTERIM</status_change>
				<status_change date="2004-10-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-490" comment="the version of shell32.dll is less than 4.0.1381.7116" />
					<criterion test_ref="wrt-288" negate="true" comment="Patch Q313829 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL19" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2002-0189</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL20" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0715</cveid>
			<dates>
				<created date="2004-11-02"/>
				<modified date="2004-11-02"></modified>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-568" comment="the version of rpcss.dll is less than 5.0.2195.6810" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL22" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2002-0147</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun.</description>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL23" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0026</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL24" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>FTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0073</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-202" comment="FTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL25" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0079</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL26" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Network Connection Manager (NCM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2002-0720</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
					<criterion test_ref="wft-207" comment="the version of netman.dll is less than 5.0.2195.5974" />
					<criterion test_ref="wrt-229" negate="true" comment="Patch Q326886 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL27" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0193</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-208" comment="the version of mshtml.dll is less than 5.0.3504.2500" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-215" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL28" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>skk</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0539</cveid>
			<dates>
				<created date="2003-09-04"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-216" comment="Vulnerable config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL29" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0364</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.</description>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-209" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" />
					<criterion test_ref="wrt-238" negate="true" comment="Patch Q321599 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL30" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2002-0055</cveid>
			<dates>
				<created date="2003-05-20"/>
				<modified date="2004-03-30">Changed the registry key in question for the SMTP enabled check to SMTPSVC from SMTP.</modified>
			</dates>
			<description>SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 to cause a denial of service via a command with a malformed data transfer (BDAT) request</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-210" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" />
					<criterion test_ref="wrt-239" negate="true" comment="Patch Q313450" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL31" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0033</cveid>
			<dates>
				<created date="2003-01-31"/>
			</dates>
			<description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
					<criterion test_ref="spt-207" negate="true" comment="Patch 110896-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL32" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0026</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL33" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Xsun</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0158</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-206" comment="File Xsun exists" />
					<criterion test_ref="spt-208" negate="true" comment="Patch 108376-38 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-210" comment="File Xsun SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL34" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>whodo</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2001-1076</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-209" comment="File whodo exists" />
					<criterion test_ref="spt-209" negate="true" comment="Patch 111600-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-219" comment="File whodo SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL35" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>FTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0073</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters</description>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-202" comment="FTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL37" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2001-0333</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-211" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" />
					<criterion test_ref="wrt-241" negate="true" comment="Patch Q295534 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-243" negate="true" comment="Windows NT 4.0 Security Roll-up Package" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL38" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0051</cveid>
			<dates>
				<created date="2003-05-13"/>
			</dates>
			<description>Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" />
					<criterion test_ref="wft-212" comment="the version of srvsvc.dll is less than 5.00.2195.4980" />
					<criterion test_ref="wrt-246" negate="true" comment="Patch Q318593 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL39" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0150</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL40" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0023</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL41" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>rpc.rwalld</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0573</cveid>
			<dates>
				<created date="2003-01-30"/>
			</dates>
			<description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-210" comment="File rpc.rwalld exists" />
					<criterion test_ref="spt-210" negate="true" comment="Patch 112899-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-221" comment="File rpc.rwalld executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL42" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>libnsl</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0391</cveid>
			<dates>
				<created date="2003-01-02"/>
			</dates>
			<description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" />
					<criterion test_ref="cmp-223" negate="true" comment="Patches 106942-22 and 108451-06" />
				</software>
				<configuration>
					<criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL43" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0084</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL44" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2000-0884</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-213" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" />
					<criterion test_ref="wrt-247" negate="true" comment="Patch Q269862 Installed" />
					<criterion test_ref="wrt-248" negate="true" comment="Patch Q277873 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL45" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0071</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL46" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0074</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL47" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>whodo</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2001-1076</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-209" comment="File whodo exists" />
					<criterion test_ref="spt-213" negate="true" comment="Patch 111826-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-219" comment="File whodo SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL48" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0088</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL49" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2003-1326</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-230" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-214" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-252" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL50" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1, or Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0023</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-215" comment="the version of mshtml.dll is less than 5.0.3502.4856" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL52" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>EOG</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0165</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-205" comment="eog version is less than 2.2.0-2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-232" comment="eog is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL54" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2003-0081</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL55" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0159</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL56" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>rpc.yppasswdd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0779</cveid>
			<dates>
				<created date="2002-08-30"/>
			</dates>
			<description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-212" comment="File rpc.yppasswdd exists" />
					<criterion test_ref="spt-214" negate="true" comment="Patch 111596-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-204" comment="rpc.yppasswdd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL57" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2003-1328</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL58" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0075</cveid>
			<dates>
				<created date="2003-08-20"/>
			</dates>
			<description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL59" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2002-1561</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-217" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" />
					<criterion test_ref="wrt-253" negate="true" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" />
					<criterion test_ref="wrt-254" negate="true" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL60" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0088</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL61" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0366</cveid>
			<dates>
				<created date="2003-04-04"/>
			</dates>
			<description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wrt-256" comment="RAS Phonebook" />
					<criterion test_ref="wft-218" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" />
					<criterion test_ref="wrt-257" negate="true" comment="Patch Q318138 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL62" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>mibiisa</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0797</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-213" comment="File mibiisa exists" />
					<criterion test_ref="spt-215" negate="true" comment="Patch 107709-19 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-205" comment="mibiisa running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL63" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0366</cveid>
			<dates>
				<created date="2003-04-04"/>
			</dates>
			<description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-256" comment="RAS Phonebook" />
					<criterion test_ref="wft-219" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" />
					<criterion test_ref="wrt-257" negate="true" comment="Patch Q318138 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL64" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0018</cveid>
			<dates>
				<created date="2003-05-13"/>
				<modified date="2004-08-04"></modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-220" comment="File %windir%\system32\netlogon.dll version is less than 5.00.0893.1105" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL65" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>kcms_configure</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0594</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-201" comment="File kcms_configure exists" />
					<criterion test_ref="spt-216" negate="true" comment="Patch 107337-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL66" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2003-0223</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL67" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0089</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
					<criterion test_ref="spt-217" negate="true" comment="Patch 110453-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL68" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0089</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
					<criterion test_ref="spt-218" negate="true" comment="Patch 108721-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL69" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0356</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL70" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>dtspcd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0803</cveid>
			<dates>
				<created date="2002-08-23"/>
			</dates>
			<description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary command</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-214" comment="File dtspcd exists" />
					<criterion test_ref="spt-219" negate="true" comment="Patch 108949-07 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-239" comment="File dtspcd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL71" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
			</contributors>
			<cveid status="CVE">2001-0344</cveid>
			<dates>
				<created date="2003-06-24"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-222" comment="File sqlservr.exe version3 is less than 296" />
				</software>
				<configuration>
					<criterion test_ref="wrt-261" comment="Mixed Mode Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL72" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0147</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun.</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL73" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0357</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL74" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>dtspcd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0803</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary command</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-214" comment="File dtspcd exists" />
					<criterion test_ref="spt-220" negate="true" comment="Patch 106934-04 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-239" comment="File dtspcd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL75" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0428</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the DCERPC dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL76" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0367</cveid>
			<dates>
				<created date="2003-04-04"/>
			</dates>
			<description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-223" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" />
					<criterion test_ref="wrt-262" negate="true" comment="Patch Q320206 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL77" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0023</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL78" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2001-0333</cveid>
			<dates>
				<created date="2003-10-10"/>
				<modified date="2004-08-04"></modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-224" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL79" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>rpc.rwalld</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0573</cveid>
			<dates>
				<created date="2003-01-30"/>
			</dates>
			<description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-210" comment="File rpc.rwalld exists" />
					<criterion test_ref="spt-221" negate="true" comment="Patch 112846-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-221" comment="File rpc.rwalld executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL80" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0678</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-222" negate="true" comment="Patch 107893-19 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL81" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0148</cveid>
			<dates>
				<created date="2003-08-20"/>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL82" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2001-0509</cveid>
			<dates>
				<created date="2003-08-27"/>
			</dates>
			<description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-225" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" />
					<criterion test_ref="wft-59" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" />
					<criterion test_ref="wft-89" negate="true" comment="File sqlservr.exe version3 greater than or equal to 384" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL83" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2001-0542</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CAN-2001-0879</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-227" comment="File sqlservr.exe version3 less than 428" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL84" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0429</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL86" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>lbxproxy</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0090</cveid>
			<dates>
				<created date="2002-08-30"/>
			</dates>
			<description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-215" comment="File lbxproxy exists" />
					<criterion test_ref="spt-223" negate="true" comment="Patch 108652-51 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL87" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-0013</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL88" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0430</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL89" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Multiple UNC Provider (MUP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0151</cveid>
			<dates>
				<created date="2003-05-13"/>
			</dates>
			<description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-229" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" />
					<criterion test_ref="wrt-265" negate="true" comment="Patch Q311967 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL90" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CVE">2001-0151</cveid>
			<dates>
				<created date="2003-10-10"/>
				<modified date="2004-10-20">corrected configuration criterion</modified>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-230" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" />
					<criterion test_ref="wrt-266" negate="true" comment="Patch Q291845 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-541" negate="true" comment="WebDav is disabled(for iis 5.0)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL91" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0677</cveid>
			<dates>
				<created date="2003-01-31"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-222" negate="true" comment="Patch 107893-19 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL92" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-0148</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL94" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mibiisa</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0797</cveid>
			<dates>
				<created date="2002-09-25"/>
			</dates>
			<description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-213" comment="File mibiisa exists" />
					<criterion test_ref="spt-204" negate="true" comment="Patch 108869-16 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-205" comment="mibiisa running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL95" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0149</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL96" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2002-0078</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-03-04">Added the configuration check to see if cookies are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability</description>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-231" comment="the version of mshtml.dll is less than 6.0.2715.400" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-250" comment="cookies are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL97" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0084</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL98" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2002-0371</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-232" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-271" comment="Gopher Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL99" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2002-0193</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-215" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL101" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0431</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL102" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>rpc.yppasswdd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0779</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-212" comment="File rpc.yppasswdd exists" />
					<criterion test_ref="spt-224" negate="true" comment="Patch 111590-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-204" comment="rpc.yppasswdd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL103" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Locator service</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2003-0003</cveid>
			<dates>
				<created date="2003-08-27"/>
			</dates>
			<description>Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-233" comment="the version of locator.exe is less than 4.0.1381.7202" />
					<criterion test_ref="wrt-272" negate="true" comment="Patch Q810833 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-273" comment="Locator Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL106" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0432</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL107" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ximian Evolution</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0128</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL108" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ximian Evolution</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0129</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL109" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0109</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-234" comment="the version of ntdll.dll is less than 5.0.2195.6685" />
					<criterion test_ref="wrt-274" negate="true" comment="the patch q815021 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL111" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ximian Evolution</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0130</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL112" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0547</cveid>
			<dates>
				<created date="2003-09-04"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL113" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0548</cveid>
			<dates>
				<created date="2003-09-04"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CAN-2003-0549</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL114" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>snmpdx</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0796</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-205" comment="File snmpdx exists" />
					<criterion test_ref="spt-215" negate="true" comment="Patch 107709-19 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-203" comment="snmpdx running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL117" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2003-0526</cveid>
			<dates>
				<created date="2003-10-03"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" />
					<criterion test_ref="wrt-276" negate="true" comment="ISA2000-KB816456-x86.exe" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL118" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0345</cveid>
			<dates>
				<created date="2003-09-08"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-235" comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" />
					<criterion test_ref="wrt-277" negate="true" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL120" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>kcms_server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2003-0027</cveid>
			<dates>
				<created date="2003-01-30"/>
			</dates>
			<description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-216" comment="File kcms_server exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL121" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2002-0154</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-236" comment="the version of sqlservr.exe is less than 2000.80.608.0" />
					<criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL123" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0809</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" />
					<criterion test_ref="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-75" comment="ActiveX controls are enabled" />
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL124" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0033</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL126" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2003-1326</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL127" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2003-0528</cveid>
			<dates>
				<created date="2003-09-15"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0715</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL129" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0549</cveid>
			<dates>
				<created date="2003-09-04"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL130" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0071</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL131" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>xlock</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0652</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-204" comment="File xlock exists" />
					<criterion test_ref="spt-225" negate="true" comment="Patch 108376-30 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-209" comment="File xlock SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL132" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0149</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL133" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GNU Ghostscript</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0354</cveid>
			<dates>
				<created date="2003-08-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-211" comment="ghostscript version is less than 7.05-32.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-262" comment="/usr/bin/gs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL134" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0010</cveid>
			<dates>
				<created date="2004-11-02"/>
				<modified date="2004-11-02"></modified>
				<modified date="2004-11-02"></modified>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1157" comment="jscript.dll version is 5.1, 5.5, or 5.6 " />
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="cmp-1156" negate="true" comment="The patch js56nen.exe is installed for version 5.1, 5.5, or 5.6" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL135" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GnuPG</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0255</cveid>
			<dates>
				<created date="2003-08-19"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-212" comment="gnupg version is less than 1.2.1-4" />
				</software>
				<configuration>
					<criterion test_ref="cmp-263" comment="/usr/bin/gnupg is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL136" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Microsoft Virtual Machine (VM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2003-0111</cveid>
			<dates>
				<created date="2004-04-30"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wft-301" comment="the version of msjava.dll is less than 5.0.3810.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL137" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0150</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL138" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GtkHTML</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0133</cveid>
			<dates>
				<created date="2003-09-02"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-213" comment="gtkhtml version is less than 1.1.9-0.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL139" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
			</contributors>
			<cveid status="CAN">2001-0046</cveid>
			<dates>
				<created date="2004-06-08"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1012" comment="For Terminal Server" />
					<criterion test_ref="wrt-454" negate="true" comment="Patch Q265714 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL140" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Transaction Server (MTS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
			</contributors>
			<cveid status="CAN">2001-0047</cveid>
			<dates>
				<created date="2004-06-08"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1012" comment="For Terminal Server" />
					<criterion test_ref="wrt-454" negate="true" comment="Patch Q265714 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-455" comment="MTS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL141" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2001-0154</cveid>
			<dates>
				<created date="2003-07-18"/>
				<modified date="2004-03-04">Added the configuration check to see if file downloads are enabled by the current user when local machine settings are not in use.  Changed the status from ACCEPTED to INTERIM</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-264" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-240" comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" />
					<criterion test_ref="wrt-284" negate="true" comment="the patch q290108 is installed" />
					<criterion test_ref="wrt-285" negate="true" comment="the patch q295106 is installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-265" comment="file downloads are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL142" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0112</cveid>
			<dates>
				<created date="2004-11-02"/>
				<modified date="2004-11-02"></modified>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-536" negate="true" comment="Windows NT Service Pack 6a is installed" />
					<criterion test_ref="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL143" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1186</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL144" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-0012</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL145" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Multiple UNC Provider (MUP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0151</cveid>
			<dates>
				<created date="2003-05-13"/>
			</dates>
			<description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-243" comment="the version of mup.sys is less than 4.0.1381.7125" />
					<criterion test_ref="wrt-287" negate="true" comment="Patch Q312895 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL146" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0345</cveid>
			<dates>
				<created date="2004-11-02"/>
				<modified date="2004-11-02"></modified>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-569" negate="true" comment="Patch Q817606 Installed" />
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-566" comment="The version of srv.sys is less than 4.0.1381.7214" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL147" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2002-0070</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-244" comment="the version of shell32.dll is less than 5.00.3502.4718" />
					<criterion test_ref="wrt-288" negate="true" comment="Patch Q313829 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL148" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GtkHTML</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0541</cveid>
			<dates>
				<created date="2003-09-10"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-214" comment="gtkhtml version is less than 1.1.9-0.9.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-266" comment="/usr/bin/evolution is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL149" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>fs.auto, xfs</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-1317</cveid>
			<dates>
				<created date="2003-09-08"/>
			</dates>
			<description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-217" comment="File fs.auto exists" />
					<criterion test_ref="sft-218" comment="File xfs exists" />
					<criterion test_ref="spt-226" negate="true" comment="Patch 109862-03 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-267" comment="File xfs executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL150" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2003-0020</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL151" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0083</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CAN-2003-0020</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL152" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>fs.auto, xfs</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-1317</cveid>
			<dates>
				<created date="2003-09-08"/>
			</dates>
			<description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-217" comment="File fs.auto exists" />
					<criterion test_ref="sft-218" comment="File xfs exists" />
					<criterion test_ref="spt-227" negate="true" comment="Patch 108117-06 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-267" comment="File xfs executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL156" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0132</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL158" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0367</cveid>
			<dates>
				<created date="2003-04-04"/>
			</dates>
			<description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-245" comment="the version of smss.exe is less than 4.0.1381.7152" />
					<criterion test_ref="wrt-262" negate="true" comment="Patch Q320206 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL159" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0018</cveid>
			<dates>
				<created date="2003-05-13"/>
			</dates>
			<description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-246" comment="the version of netlogon.dll is less than 4.0.1381.7092" />
					<criterion test_ref="wrt-243" negate="true" comment="Windows NT 4.0 Security Roll-up Package" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL161" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-0012</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL169" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0192</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-203" comment="httpd.worker is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL173" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0253</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL175" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0678</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-206" negate="true" comment="Patch 110286-09 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL177" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0679</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-228" negate="true" comment="Patch 107893-20 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL178" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2003-1326</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-247" comment="the version of mshtml.dll is less than 5.50.4923.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-252" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL179" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>lbxproxy</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0090</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-215" comment="File lbxproxy exists" />
					<criterion test_ref="spt-229" negate="true" comment="Patch 107654-10 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL182" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0364</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-248" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" />
					<criterion test_ref="wrt-289" negate="true" comment="Patch Q321599 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL183" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0254</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL185" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Authenticode</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0660</cveid>
			<dates>
				<created date="2003-10-29"/>
				<modified date="2004-03-04">Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.</modified>
				<modified date="2004-03-05">Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.</modified>
				<modified date="2004-09-13">The compound test that includes SP1 or earlier has been added</modified>
				<modified date="2004-09-13"></modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-273" comment="a vulnerable version of cryptui.dll exists" />
					<criterion test_ref="wrt-293" negate="true" comment="Patch WindowsXP-KB823182-x86-ENU Installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-275" comment="downloading of signed ActiveX controls is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL188" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0664</cveid>
			<dates>
				<created date="2004-08-25"/>
				<modified date="2004-08-25">Added word 2000 and winword.exe information</modified>
				<modified date="2004-08-25">changed to word 2000</modified>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-470" comment="the version of winword.exe is less than 9.0.0.7924" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL189" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2002-0724</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service"</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-251" comment="the version of xactsrv.dll is less than 5.0.2195.5971" />
					<criterion test_ref="wrt-295" negate="true" comment="Patch Q326830 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-296" comment="Lanman enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL190" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Certificate Enrollment Control</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2002-0699</cveid>
			<dates>
				<created date="2003-10-10"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-252" comment="the version of xenroll.dll is less than 5.131.3659.0" />
					<criterion test_ref="wrt-297" negate="true" comment="Patch Q323172 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-276" comment="ActiveX Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL191" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2000-0886</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-253" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" />
					<criterion test_ref="wrt-248" negate="true" comment="Patch Q277873 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL192" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0679</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-230" negate="true" comment="Patch 110286-10 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL193" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>KDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0690</cveid>
			<dates>
				<created date="2003-09-21"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-217" comment="kdebase version is less than 3.1-15" />
				</software>
				<configuration>
					<criterion test_ref="cmp-278" comment="/usr/bin/kdm is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL194" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0352</cveid>
			<dates>
				<created date="2004-11-02"/>
				<modified date="2004-11-02"></modified>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-570" negate="true" comment="Patch Q823980 Installed" />
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-567" comment="the version of rpcss.dll is less than 4.0.1381.7203" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL195" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>kcms_server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2003-0027</cveid>
			<dates>
				<created date="2003-01-24"/>
			</dates>
			<description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-216" comment="File kcms_server exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL197" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2001-0500</cveid>
			<dates>
				<created date="2004-01-14"/>
				<modified date="2004-08-04"></modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-254" comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" />
					<criterion test_ref="wrt-299" negate="true" comment="Patch Q300972 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-205" comment="idq.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL198" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0660</cveid>
			<dates>
				<created date="2003-10-16"/>
				<modified date="2004-03-04">Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-255" comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" />
					<criterion test_ref="wrt-293" negate="true" comment="Patch WindowsXP-KB823182-x86-ENU Installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-275" comment="downloading of signed ActiveX controls is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL199" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Data Protocol (RDP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2002-0863</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-300" comment="Terminal Server Version" />
					<criterion test_ref="wft-256" comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" />
					<criterion test_ref="wrt-301" negate="true" comment="Patch Q324380 installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-302" comment="RDP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL200" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Windows Script Engine for JScript v5.6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0010</cveid>
			<dates>
				<created date="2003-08-27"/>
				<modified date="2004-03-03">Corrected to reflect the unification of the Windows Schema</modified>
				<modified date="2004-03-04">Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.</modified>
				<modified date="2004-08-24">Added Patch to Definition</modified>
				<modified date="2004-08-24">negated patch</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-257" comment="the version of jscript.dll is less than 5.6.0.8513" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
					<criterion test_ref="wrt-499" negate="true" comment="the patch js56nen.exe (5.6.0.8513 version) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-76" comment="active scripting is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL201" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows XP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0659</cveid>
			<dates>
				<created date="2003-10-28"/>
				<modified date="2004-03-05">Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.</modified>
				<modified date="2004-09-13"></modified>
				<modified date="2004-09-13">The compound test that includes a check for SP1 or earlier has been added</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-282" comment="a vulnerable version of user32.dll exists" />
					<criterion test_ref="wrt-304" negate="true" comment="the patch kb824141 is installed (Hotfix key)" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-305" comment="the utility manager Service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL202" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2002-1143</cveid>
			<dates>
				<created date="2004-08-24"/>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-478" comment="the version of winword.exe is less than 9.0.0.6926" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL203" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1187</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &lt;frame&gt; or &lt;iframe&gt; element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL204" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0838</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CAN-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" />
					<criterion test_ref="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-75" comment="ActiveX controls are enabled" />
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL205" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CVE">2002-1056</cveid>
			<dates>
				<created date="2004-09-06"/>
				<modified date="2004-09-07">made into a real definition</modified>
				<status_change date="2004-09-08">DRAFT</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-486" comment="the version of winword.exe is less than 9.0.0.6328" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL206" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1048</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL207" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0549</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifiying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-266" comment="the version of mshtml.dll is less than 6.00.3790.191" />
					<criterion test_ref="wrt-237" negate="true" comment="the patch kb867801 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL209" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2002-0053</cveid>
			<dates>
				<created date="2003-12-03"/>
			</dates>
			<description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request.  NOTE: this candidate may be split or merged with other candidates.  This and other PROTOS-related candidates, especially CAN-2002-0012 and CAN-2002-0013, will be updated when more accurate information is available</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL210" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-0075</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL212" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1048</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL213" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Messenger Service</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0717</cveid>
			<dates>
				<created date="2003-10-16"/>
				<modified date="2004-03-29">Fixed an error in the configuration section, now correctly testing that messenger service is enabled.  Before it was testing that HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start=2, now it is testing that it does not equal 4.</modified>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-122" comment="the version of msgsvc.dll is less than 5.0.2195.6861" />
					<criterion test_ref="wft-260" comment="the version of wkssvc.dll is less than 5.0.2195.6861" />
					<criterion test_ref="wrt-83" negate="true" comment="the patch q828035 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-307" comment="the messenger service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL215" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>KDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0692</cveid>
			<dates>
				<created date="2003-09-21"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-217" comment="kdebase version is less than 3.1-15" />
				</software>
				<configuration>
					<criterion test_ref="cmp-278" comment="/usr/bin/kdm is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL216" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0566</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-279" comment="the version of mshtml.dll is less than 5.00.3819.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL217" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0711</cveid>
			<dates>
				<created date="2003-10-16"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" />
					<criterion test_ref="wrt-308" negate="true" comment="Patch KB825119 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-309" negate="true" comment="HCP Protocol" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL218" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0346</cveid>
			<dates>
				<created date="2004-11-02"/>
				<modified date="2004-11-02"></modified>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-569" comment="the version of quartz.dll is less than 6.1.5.132" />
					<criterion test_ref="wrt-571" negate="true" comment="Patch Q19696 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL225" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1187</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &lt;frame&gt; or &lt;iframe&gt; element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL230" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0028</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CAN-2002-0391</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-218" comment="krb5-server version is less than 1.2.7-14" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL231" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2000-1081</cveid>
			<dates>
				<created date="2003-08-27"/>
			</dates>
			<description>The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-85" comment="File odsole70.dll Version3 is less than 223" />
					<criterion test_ref="wft-86" comment="File xpqueue.dll Version3 is less than 223" />
					<criterion test_ref="wft-87" comment="File xprepl.dll Version3 is less than 223" />
					<criterion test_ref="wft-88" comment="File xpstar.dll Version3 is less than 223" />
					<criterion test_ref="wft-89" negate="true" comment="File sqlservr.exe version3 greater than or equal to 384" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL235" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2003-0230</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Microsoft SQL Server 7, 2000, and MSDE allows local users go gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-70" comment="File console.exe version3 is less than 818" />
					<criterion test_ref="wft-71" comment="File dbmslpcn.dll version3 is less than 818" />
					<criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 811" />
					<criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 765" />
					<criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" />
					<criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" />
					<criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" />
					<criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" />
					<criterion test_ref="wft-61" comment="File msgprox.dll version3 is less than 765" />
					<criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" />
					<criterion test_ref="wft-63" comment="File replrec.dll version3 is less than 765" />
					<criterion test_ref="wft-64" comment="File sqlvdi.dll version3 is less than 765" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL236" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1048</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-267" comment="the version of mshtml.dll is less than 6.00.2800.1458" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL237" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0662</cveid>
			<dates>
				<created date="2003-10-17"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML formatter e-mail or web page</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-271" comment="the version of tshoot.ocx is less than 1.0.1.2125" />
					<criterion test_ref="wrt-310" negate="true" comment="the patch kb826232 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-75" comment="ActiveX controls are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL241" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0549</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifiying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL244" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0082</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun")</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-218" comment="krb5-server version is less than 1.2.7-14" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL246" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0574</cveid>
			<dates>
				<created date="2004-10-26"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1153" comment="Exchange Server 2003 is installed on Windows Server 2003" />
					<criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" />
					<criterion test_ref="wrt-548" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL248" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0138</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-219" comment="krb5-libs version is less than 1.2.7-14" />
					<criterion test_ref="cmp-289" comment="krb5-server or krb5-workstation installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL250" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0139</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-219" comment="krb5-libs version is less than 1.2.7-14" />
					<criterion test_ref="cmp-289" comment="krb5-server or krb5-workstation installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL253" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CVE">2001-0879</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-312" negate="true" comment="Patch Q305601 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL254" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0127</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rrt-202" comment="kernel version = 2.4.20-6" />
				</software>
				<configuration>
					<criterion test_ref="rut-204" comment="kernel 2.4.20-6 or earlier is running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL260" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Netfilter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0187</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL261" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Netfilter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0244</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL262" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0112</cveid>
			<dates>
				<created date="2004-11-02"/>
				<modified date="2004-11-02"></modified>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-570" comment="the version of kernel32.dll is less than 5.0.2195.6011" />
					<criterion test_ref="wrt-478" comment="the patch Q811493 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL264" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2003-0715</cveid>
			<dates>
				<created date="2003-12-03"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL268" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows XP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0717</cveid>
			<dates>
				<created date="2003-10-28"/>
				<modified date="2004-03-05">Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.</modified>
				<modified date="2004-09-13">CMP-66 has been added</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-30" comment="a vulnerable version of wkssvc.dll exists" />
					<criterion test_ref="cmp-295" comment="a vulnerable version of msgsvc.dll exists" />
					<criterion test_ref="wrt-83" negate="true" comment="the patch q828035 is installed (Hotfix key)" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-307" comment="the messenger service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL271" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2002-0056</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-274" comment="File sqlservr.exe version3 is less than 578" />
					<criterion test_ref="wft-275" comment="File xpstar.dll version3 is less than 561" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL272" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-1217</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &lt;frame&gt; and &lt;iframe&gt; domain restrictions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL277" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMB Signing (Server Message Block)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2002-1256</cveid>
			<dates>
				<created date="2003-09-16"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-276" comment="the version of srvsvc.dll is less than 5.0.2195.6110" />
					<criterion test_ref="wrt-314" negate="true" comment="Patch Q329170 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-315" comment="SMB Signing enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL278" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0246</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL281" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Media Player for Windows XP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0372</cveid>
			<dates>
				<created date="2003-11-26"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the IE cache, aka the "Cache Path Disclosure via Windows Media Player"</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" />
					<criterion test_ref="wft-277" comment="the version of dxmasf.dll is less than 6.4.9.1121" />
					<criterion test_ref="wft-140" comment="the version of msdxm.ocx is less than 6.4.9.1124" />
					<criterion test_ref="wft-141" comment="the version of wmpcore.dll is less than 8.0.0.4482" />
					<criterion test_ref="wft-142" comment="the version of wmplayer.exe is less than 8.0.0.4482" />
					<criterion test_ref="wrt-317" negate="true" comment="Patch wm320920_8.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL284" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0247</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops")</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL287" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Media Player for Windows XP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2001-0719</cveid>
			<dates>
				<created date="2003-11-26"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" />
					<criterion test_ref="wft-143" comment="the version of msdxm.ocx is less than 6.4.9.1121" />
					<criterion test_ref="wft-277" comment="the version of dxmasf.dll is less than 6.4.9.1121" />
					<criterion test_ref="wrt-318" negate="true" comment="Patch wm308567 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL291" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2002-0624</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-278" comment="the version of sqlservr.exe is less than 2000.80.650.0" />
					<criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" />
				</software>
				<configuration>
					<criterion test_ref="wrt-261" comment="Mixed Mode Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL292" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0248</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL294" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>MDAC 2.6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CVE">2002-1142</cveid>
			<dates>
				<created date="2004-08-24"/>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-481" comment="the version of msadco.dll is less than 2.62.9119.1" />
					<criterion test_ref="wrt-503" negate="true" comment="Patch Q329414 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL295" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0364</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL296" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2003-0352</cveid>
			<dates>
				<created date="2003-12-03"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-280" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" />
					<criterion test_ref="wrt-254" negate="true" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL298" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-0013</cveid>
			<dates>
				<created date="2003-10-10"/>
				<modified date="2004-09-20">Changed CAN-2002-0012 to CAN-2002-0013.</modified>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL299" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2003-0231</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-70" comment="File console.exe version3 is less than 818" />
					<criterion test_ref="wft-50" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 811" />
					<criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 765" />
					<criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" />
					<criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" />
					<criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" />
					<criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" />
					<criterion test_ref="wft-55" comment="the version of msgprox.dll is less than 2000.80.765.0" />
					<criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" />
					<criterion test_ref="wft-56" comment="the version of replrec.dll is less than 2000.80.765.0" />
					<criterion test_ref="wft-57" comment="the version of sqlvdi.dll is less than 2000.80.765.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL303" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2003-0232</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-70" comment="File console.exe version3 is less than 818" />
					<criterion test_ref="wft-50" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 811" />
					<criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 765" />
					<criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" />
					<criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" />
					<criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" />
					<criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" />
					<criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" />
					<criterion test_ref="wft-55" comment="the version of msgprox.dll is less than 2000.80.765.0" />
					<criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" />
					<criterion test_ref="wft-56" comment="the version of replrec.dll is less than 2000.80.765.0" />
					<criterion test_ref="wft-57" comment="the version of sqlvdi.dll is less than 2000.80.765.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL304" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>/proc/tty/driver/serial</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0461</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL306" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0566</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL308" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0824</cveid>
			<dates>
				<created date="2003-12-09"/>
				<modified date="2004-01-14">Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.0.2.7523" />
					<criterion test_ref="wrt-88" negate="true" comment="the patch q810217 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL309" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0462</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL311" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0464</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL316" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2002-0641</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-278" comment="the version of sqlservr.exe is less than 2000.80.650.0" />
					<criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" />
					<criterion test_ref="wft-58" comment="the version of impprov.dll is less than 2000.80.650.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL319" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0525</cveid>
			<dates>
				<created date="2003-10-10"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-40" negate="true" comment="this is an NT Workstation" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-282" comment="the version of kernel32.dll is less than 4.0.1381.7224" />
					<criterion test_ref="wrt-323" negate="true" comment="Patch Q823803 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL321" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Media Player for Windows XP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2003-0228</cveid>
			<dates>
				<created date="2003-11-26"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" />
					<criterion test_ref="wft-144" comment="the version of wmplayer.exe is less than 8.0.0.4490" />
					<criterion test_ref="wrt-324" negate="true" comment="Patch WindowsMedia8-KB817787-x86-ENU.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL322" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0566</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL327" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0476</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL328" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0501</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL331" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Windows Workstation Service</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0812</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-03-08">Added 64-bit edition support to this definition allowing us to deprecated OVAL332</modified>
				<modified date="2004-09-13"></modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-30" comment="a vulnerable version of wkssvc.dll exists" />
					<criterion test_ref="wrt-83" negate="true" comment="the patch q828035 is installed (Hotfix key)" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-71" comment="the workstation service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL333" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-1217</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &lt;frame&gt; and &lt;iframe&gt; domain restrictions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL334" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2001-0543</cveid>
			<dates>
				<created date="2003-09-16"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
					<criterion test_ref="wft-283" comment="the version of nntpsvc.dll is less than 5.0.2195.3881" />
					<criterion test_ref="wrt-325" negate="true" comment="Patch Q303984 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL335" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0814</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL336" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0820</cveid>
			<dates>
				<created date="2003-11-19"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-19" comment="the version of winword.exe is less than 9.0.0.8216" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL340" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0659</cveid>
			<dates>
				<created date="2003-10-16"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-285" comment="File %windir%\system32\user32.dll version is less than 5.00.2195.6799" />
					<criterion test_ref="wrt-304" negate="true" comment="the patch kb824141 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-305" comment="the utility manager Service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL341" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0814</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL342" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0814</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL343" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0814</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL344" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0814</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL349" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0814</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL351" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0815</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp2 installed.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL352" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0815</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp3 installed.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL353" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0815</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp4 installed.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL356" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0815</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL357" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0815</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL359" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0815</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL361" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0816</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL362" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0816</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL363" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0816</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL364" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0822</cveid>
			<dates>
				<created date="2003-12-09"/>
				<modified date="2004-03-05">Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" />
					<criterion test_ref="wrt-88" negate="true" comment="the patch q810217 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL366" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0822</cveid>
			<dates>
				<created date="2003-12-09"/>
				<modified date="2004-03-05">Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.</modified>
				<modified date="2004-09-14">XP SP2 added</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-77" comment="Windows NT, 2000, or XP is installed" />
					<criterion test_ref="cmp-113" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL367" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SharePoint Team Services</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0822</cveid>
			<dates>
				<created date="2003-12-09"/>
				<modified date="2004-03-05">Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.</modified>
				<modified date="2004-09-14">XP SP2 added</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-78" comment="Windows 2000, XP, or 2003 is installed" />
					<criterion test_ref="cmp-113" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL368" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0823</cveid>
			<dates>
				<created date="2003-12-18"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL369" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0823</cveid>
			<dates>
				<created date="2003-12-18"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL370" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0823</cveid>
			<dates>
				<created date="2003-12-18"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL371" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0823</cveid>
			<dates>
				<created date="2003-12-18"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL372" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0823</cveid>
			<dates>
				<created date="2003-12-18"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL373" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0225</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL374" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help ActiveX Control</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2002-0693</cveid>
			<dates>
				<created date="2003-09-18"/>
				<modified date="2004-03-04">Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-286" comment="the version of hhctrl.ocx is less than 5.2.3669.0" />
					<criterion test_ref="wft-287" comment="the version of hhsetup.dll is less than 5.2.3644.0" />
					<criterion test_ref="wft-102" comment="the version of itircl.dll is less than 5.2.3644.0" />
					<criterion test_ref="wft-103" comment="the version of itss.dll is less than 5.2.3644.0" />
					<criterion test_ref="wrt-328" negate="true" comment="the patch q323255 is installed (Hotfix key)" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-76" comment="active scripting is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL380" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0550</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL384" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0551</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL385" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0552</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL386" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0619</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL387" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0699</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CAN-2003-0700</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL388" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-1254</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL392" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0814</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.</modified>
				<modified date="2004-03-04">Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL393" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1185</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL401" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0700</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CAN-2003-0699</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL402" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
			</contributors>
			<cveid status="CAN">2002-0053</cveid>
			<dates>
				<created date="2004-09-15"/>
				<modified date="2004-09-15">Filled out initial submission.  Now a complete definition.</modified>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request.  NOTE: this candidate may be split or merged with other candidates.  This and other PROTOS-related candidates, especially CAN-2002-0012 and CAN-2002-0013, will be updated when more accurate information is available</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL403" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2002-0694</cveid>
			<dates>
				<created date="2003-09-30"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-287" comment="the version of hhsetup.dll is less than 5.2.3644.0" />
					<criterion test_ref="wft-102" comment="the version of itircl.dll is less than 5.2.3644.0" />
					<criterion test_ref="wft-103" comment="the version of itss.dll is less than 5.2.3644.0" />
					<criterion test_ref="wrt-328" negate="true" comment="the patch q323255 is installed (Hotfix key)" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL406" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2003-0110</cveid>
			<dates>
				<created date="2003-12-03"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" />
					<criterion test_ref="wft-100" comment="the version of w3proxy.exe is less than 3.0.1200.257" />
					<criterion test_ref="wft-101" comment="the version of wpsrv.exe is less than 3.0.1200.257" />
					<criterion test_ref="wrt-331" negate="true" comment="Patch isahf257 installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-332" comment="Microsoft Firewall Service Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL408" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-1254</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL409" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0816</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL411" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Konqueror</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0459</cveid>
			<dates>
				<created date="2003-09-04"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-224" comment="kdelibs version is less than 3.1-12" />
				</software>
				<configuration>
					<criterion test_ref="cmp-304" comment="/usr/bin/konqueror is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL416" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0816</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL423" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>LPRng</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0136</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-225" comment="lprng version is less than 3.8.19-3.1" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ret-255" comment="psbanner is world-executable" />
					<criterion test_ref="rlt-204" comment="lpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL424" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Telnet protocol</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2002-0020</cveid>
			<dates>
				<created date="2003-10-10"/>
				<modified date="2004-07-20">Changed patch registry key value to IsInstalled</modified>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-11">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-290" comment="the version of tlntsvr.exe is less than 5.0.33668.1" />
					<criterion test_ref="wrt-333" negate="true" comment="Patch Q307298 Installed" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-334" comment="the telnet service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL429" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CVE">2002-1056</cveid>
			<dates>
				<created date="2004-08-24"/>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-133" comment="Word 2002 is installed" />
					<criterion test_ref="wft-484" comment="the version of msohev.dll less than 10.0.2609.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL430" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>lv</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0188</cveid>
			<dates>
				<created date="2003-08-19"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-226" comment="lv version is less than 4.49.4-9.9.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL434" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mutt</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0140</cveid>
			<dates>
				<created date="2003-08-18"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-227" comment="mutt version is less than 1.4.1-1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL436" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>MySQL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2003-0073</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-205" comment="mysqld is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL442" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>MySQL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0150</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-205" comment="mysqld is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL443" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>nfs-utils</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0252</cveid>
			<dates>
				<created date="2003-09-02"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-229" comment="nfs-utils version is less than 1.0.1-3.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-206" comment="rpc.mountd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL444" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1188</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL445" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0190</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-230" comment="openssh-server version is less than 3.5p1-6.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-207" comment="sshd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL446" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0682</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CAN-2003-0693 and CAN-2003-0695</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" />
				</software>
				<configuration>
					<criterion test_ref="rlt-207" comment="sshd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL447" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0693</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CAN-2003-0695</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" />
				</software>
				<configuration>
					<criterion test_ref="rlt-207" comment="sshd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL450" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0893</cveid>
			<dates>
				<created date="2004-12-21"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP Service Pack 2" />
					<criterion test_ref="wft-327" comment="the version of lsasrv.dll is less than 5.1.2600.2525" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL451" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Utilities Manager/Windows Messaging</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0350</cveid>
			<dates>
				<created date="2003-09-09"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-291" comment="the version of sp3res.dll is less than 5.0.2195.6713" />
					<criterion test_ref="wft-292" comment="the version of umandlg.dll is less than 1.0.0.3" />
					<criterion test_ref="wrt-335" negate="true" comment="Patch KB822679 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL452" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0695</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CAN-2003-0693</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" />
				</software>
				<configuration>
					<criterion test_ref="rlt-207" comment="sshd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL459" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0816</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL461" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0131</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL466" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0147</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL469" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>pam_smb</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0686</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-237" comment="pam_smb version is less than 1.1.6-9.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL470" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>CGI.pm</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0615</cveid>
			<dates>
				<created date="2003-09-25"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-238" comment="perl-CGI version is less than 2.81-88.3" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL471" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1186</cveid>
			<dates>
				<created date="2003-08-29"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-293" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL472" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0815</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.</modified>
				<modified date="2004-03-04">Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL477" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-0904</cveid>
			<dates>
				<created date="2004-01-20"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
					<criterion test_ref="wft-34" comment="the version of exprox.dll is less than 6.5.6980.57" />
					<criterion test_ref="wrt-109" negate="true" comment="the patch KB832759 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-21" comment="this is a front-end server providing Outlook Web Access" />
					<criterion test_ref="ukn-22" comment="the back-end server is Exchange Server 2003 running on Windows 2003" />
					<criterion test_ref="wrt-106" negate="true" comment="HTTP connection reuse is disabled" />
					<criterion test_ref="ukn-20" comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL478" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Security and Acceleration Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2003-0819</cveid>
			<dates>
				<created date="2004-01-13"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" />
					<criterion test_ref="wft-33" comment="the version of h32fltr.dll is less than 3.0.1200.291" />
					<criterion test_ref="wrt-112" negate="true" comment="the patch q816458 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-108" comment="H.323 filter is enabled" />
					<criterion test_ref="wrt-107" comment="Microsoft Firewall Service is not disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL479" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0816</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.</modified>
				<modified date="2004-03-04">Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL483" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0224</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-296" comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL484" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CVE">2002-0186</cveid>
			<dates>
				<created date="2004-09-15"/>
				<modified date="2004-09-16">filling out initial submission.</modified>
				<modified date="2004-09-16">Added service pack 3 test</modified>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wrt-101" comment="MDAC 2.6 is installed" />
					<criterion test_ref="wft-491" comment="the version of sqlisapi.dll is less than 2000.80.309.0" />
					<criterion test_ref="wft-492" comment="the version of sqlservr.exe is less than 2000.80.760.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL485" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>php</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0442</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-239" comment="php version is less than 4.2.2-17.2" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL489" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CVE">2002-0186</cveid>
			<dates>
				<created date="2004-09-15"/>
				<modified date="2004-09-16">Input of initial submission.</modified>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-460" comment="SQL Server 2000 installed" />
					<criterion test_ref="wrt-102" comment="MDAC 2.7 (RTM) is installed" />
					<criterion test_ref="wft-491" comment="the version of sqlisapi.dll is less than 2000.80.309.0" />
					<criterion test_ref="wft-492" comment="the version of sqlservr.exe is less than 2000.80.760.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL490" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1025</cveid>
			<dates>
				<created date="2004-02-03"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL491" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1025</cveid>
			<dates>
				<created date="2004-02-03"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL494" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2003-0605</cveid>
			<dates>
				<created date="2003-12-03"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL495" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1186</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL499" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>pine</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0720</cveid>
			<dates>
				<created date="2003-09-12"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-240" comment="pine version is less than 4.44-19.90.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-314" comment="/usr/bin/pine is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL500" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
			</contributors>
			<cveid status="CAN">2001-0045</cveid>
			<dates>
				<created date="2003-06-08"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1012" comment="For Terminal Server" />
					<criterion test_ref="wrt-454" negate="true" comment="Patch Q265714 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL503" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>pine</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0721</cveid>
			<dates>
				<created date="2003-09-12"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-240" comment="pine version is less than 4.44-19.90.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-314" comment="/usr/bin/pine is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL507" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0566</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.00.2743.600" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL508" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0817</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL509" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1048</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-279" comment="the version of mshtml.dll is less than 5.00.3819.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL510" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1025</cveid>
			<dates>
				<created date="2004-02-03"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.00.3813.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL511" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1025</cveid>
			<dates>
				<created date="2004-02-03"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL512" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1025</cveid>
			<dates>
				<created date="2004-02-03"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.00.2737.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL513" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1025</cveid>
			<dates>
				<created date="2004-02-03"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.00.2800.1400" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL515" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0566</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL517" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1048</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-266" comment="the version of mshtml.dll is less than 6.00.3790.191" />
					<criterion test_ref="wrt-237" negate="true" comment="the patch kb867801 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL519" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0549</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifiying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.00.2743.600" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL520" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0817</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL522" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Postfix</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0468</cveid>
			<dates>
				<created date="2003-09-02"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-241" comment="postfix version is less than 1.1.12-1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-208" comment="smtpd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL525" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Data Access Compnents 2.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2003-0903</cveid>
			<dates>
				<created date="2004-01-13"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-100" comment="MDAC 2.5 is installed" />
					<criterion test_ref="wft-40" comment="the version of odbcbcp.dll is less than 3.70.11.46" />
					<criterion test_ref="wft-35" comment="the version of sqlsrv32.dll is less than 3.70.11.46" />
					<criterion test_ref="wrt-110" negate="true" comment="the patch q832483 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL526" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1025</cveid>
			<dates>
				<created date="2004-02-03"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.00.3790.118" />
					<criterion test_ref="wrt-140" negate="true" comment="the patch q832894 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL527" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1027</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL529" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1027</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL530" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1027</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.00.3813.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL531" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1027</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL532" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1027</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.00.2737.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL534" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1027</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.00.2800.1400" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL539" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0901</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL542" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1185</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL543" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0817</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.</modified>
				<modified date="2004-03-04">Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL544" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Postfix</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0540</cveid>
			<dates>
				<created date="2003-09-02"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-241" comment="postfix version is less than 1.1.12-1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-208" comment="smtpd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL548" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0817</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL549" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0817</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL552" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>smbd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0085</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" />
				</software>
				<configuration>
					<criterion test_ref="rlt-209" comment="smbd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL553" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Data Access Compnents 2.6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2003-0903</cveid>
			<dates>
				<created date="2004-01-13"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-101" comment="MDAC 2.6 is installed" />
					<criterion test_ref="wft-41" comment="the version of odbcbcp.dll is less than 2000.80.747.0" />
					<criterion test_ref="wft-36" comment="the version of sqlsrv32.dll is less than 2000.80.747.0" />
					<criterion test_ref="wrt-110" negate="true" comment="the patch q832483 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL554" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Samba</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0086</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL555" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Xsun</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CVE">2001-0422</cveid>
			<dates>
				<created date="2004-12-28"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" />
					<criterion test_ref="spt-4" negate="true" comment="Patch 108376-25 or later installed" />
					<criterion test_ref="spt-5" negate="true" comment="Patch 108652-30 or later installed" />
					<criterion test_ref="sat-12" comment="X Window System platform software (SUNWxwplt) installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL556" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0817</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL564" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Samba</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0196</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CAN-2003-0201</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" />
				</software>
				<configuration>
					<criterion test_ref="rlt-210" comment="smbd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL566" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0817</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-01-21">Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL567" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Samba, Samba-TNG</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0201</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" />
				</software>
				<configuration>
					<criterion test_ref="rlt-210" comment="smbd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL569" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>semi MIME library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0440</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-319" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-320" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL572" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0694</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-246" comment="sendmail version is less than 8.12.8-5.90" />
				</software>
				<configuration>
					<criterion test_ref="cmp-323" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL575" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Windows Workstation Service</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0812</cveid>
			<dates>
				<created date="2003-11-12"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-8" comment="the version of wkssvc.dll is less than 5.00.2195.6862" />
					<criterion test_ref="wrt-86" negate="true" comment="the patch q828748 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-71" comment="the workstation service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL582" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Microsoft Virtual Machine (VM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2002-1258</cveid>
			<dates>
				<created date="2004-04-30"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wft-302" comment="the version of msjava.dll is less than 5.0.3809.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL585" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Word 97</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0820</cveid>
			<dates>
				<created date="2003-11-19"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="ukn-10" comment="Word 97 is installed" />
					<criterion test_ref="wft-17" comment="the version of winword.exe is less than 8.0.0.9315" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL586" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Word 98</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0820</cveid>
			<dates>
				<created date="2003-11-19"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="ukn-11" comment="Word 98 is installed" />
					<criterion test_ref="wft-18" comment="the version of winword.exe is less than 8.0.0.9716" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL588" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0823</cveid>
			<dates>
				<created date="2003-12-18"/>
				<modified date="2004-01-21">Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.</modified>
				<modified date="2004-01-29">Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms</modified>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" />
					<criterion test_ref="wrt-60" negate="true" comment="the patch q824145 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL591" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0824</cveid>
			<dates>
				<created date="2003-12-09"/>
				<modified date="2004-01-14">Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.0.2.7523" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-33" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL595" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0681</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-247" comment="sendmail version is less than 8.12.8-9.90" />
				</software>
				<configuration>
					<criterion test_ref="cmp-323" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL597" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0688</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-248" comment="sendmail version is less than 8.12.8-6.90" />
				</software>
				<configuration>
					<criterion test_ref="rlt-212" comment="sendmail is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL603" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0694</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-247" comment="sendmail version is less than 8.12.8-9.90" />
				</software>
				<configuration>
					<criterion test_ref="cmp-323" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL606" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0824</cveid>
			<dates>
				<created date="2003-12-09"/>
				<modified date="2004-01-14">Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.0.2.7523" />
					<criterion test_ref="wrt-88" negate="true" comment="the patch q810217 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL614" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>SquirrelMail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0160</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-249" comment="squirrelmail version is less than 1.2.11-1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL619" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>unzip</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0282</cveid>
			<dates>
				<created date="2003-09-04"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-250" comment="unzip version is less than 5.50-33" />
				</software>
				<configuration>
					<criterion test_ref="cmp-335" comment="/usr/bin/unzip is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL625" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0824</cveid>
			<dates>
				<created date="2003-12-09"/>
				<modified date="2004-01-14">Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.</modified>
				<modified date="2004-09-14">XP SP2 added</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request</description>
			<status>INTERIM</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-77" comment="Windows NT, 2000, or XP is installed" />
					<criterion test_ref="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL629" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1027</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CAN-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.00.3790.118" />
					<criterion test_ref="wrt-140" negate="true" comment="the patch q832894 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL630" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1026</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL631" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>up2date</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0546</cveid>
			<dates>
				<created date="2003-09-03"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-251" comment="up2date version is less than 3.1.23.1-5" />
				</software>
				<configuration>
					<criterion test_ref="rct-206" comment="rhnsd is running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL634" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>vsftpd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0135</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-252" comment="vsftpd version is less than 1.1.3-8" />
				</software>
				<configuration>
					<criterion test_ref="rlt-213" comment="vsftpd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL636" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Excel 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0821</cveid>
			<dates>
				<created date="2003-11-19"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-137" comment="Excel 2000 is installed" />
					<criterion test_ref="wft-15" comment="the version of excel.exe is less than 9.0.0.8216" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL643" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1026</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL653" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-0818</cveid>
			<dates>
				<created date="2004-02-12"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-49" comment="the version of msasn1.dll is less than 5.0.2195.6823" />
					<criterion test_ref="wrt-99" negate="true" comment="the patch kb828028 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL657" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>xinetd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0211</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-17">Changed tested epoch in xinetd test rvt-253 to 2, based on testing.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-253" comment="xinetd version is less than 2:2.3.11-1.9.0" />
				</software>
				<configuration>
					<criterion test_ref="rlt-214" comment="xinetd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL664" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>xpdf</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0434</cveid>
			<dates>
				<created date="2003-08-29"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Various PDF viewers including Adobe Acrobat 5.06 and Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-254" comment="xpdf version is less than 2.0.1-11" />
				</software>
				<configuration>
					<criterion test_ref="cmp-338" comment="xpdf is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL667" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>ypserv</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0251</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-255" comment="ypserv version is less than 2.8-0.9E" />
				</software>
				<configuration>
					<criterion test_ref="rlt-215" comment="ypserv is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL668" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Word 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0820</cveid>
			<dates>
				<created date="2003-11-19"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-133" comment="Word 2002 is installed" />
					<criterion test_ref="wft-22" comment="the version of winword.exe is less than 10.0.5815.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL675" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Excel 97</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0821</cveid>
			<dates>
				<created date="2003-11-19"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="ukn-12" comment="Excel 97 is installed" />
					<criterion test_ref="wft-14" comment="the version of excel.exe is less than 8.00.01.9904" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL681" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>NetDDE Agent</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CVE">2002-1230</cveid>
			<dates>
				<created date="2004-08-24"/>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-474" comment="the version of user32.dll is less than 4.0.1381.7177" />
					<criterion test_ref="wft-475" comment="the version of gdi32.dll is less than 4.0.1381.7177" />
					<criterion test_ref="wft-476" comment="the version of winsrv.dll is less than 4.0.1381.7202" />
					<criterion test_ref="wft-477" comment="the version of win32k.sys is less than 4.0.1381.7207" />
					<criterion test_ref="wrt-502" negate="true" comment="Patch Q328310 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL685" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0571</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP Service Pack 2" />
					<criterion test_ref="wft-300" comment="the version of mswrd6.wpc is less than 10.0.803.2" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL687" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1026</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.00.3813.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL689" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1026</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL690" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-1188</cveid>
			<dates>
				<created date="2004-01-27"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL695" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Excel 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0821</cveid>
			<dates>
				<created date="2003-11-19"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-138" comment="Excel 2002 is installed" />
					<criterion test_ref="wft-16" comment="the version of excel.exe is less than 10.0.5815.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL699" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0822</cveid>
			<dates>
				<created date="2003-03-04"/>
				<modified date="2003-03-05">Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" />
				</software>
				<configuration>
					<criterion test_ref="wrt-33" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL704" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CVE">2003-0825</cveid>
			<dates>
				<created date="2004-02-12"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" />
					<criterion test_ref="wft-98" comment="the version of wins.exe is less than 5.0.2195.6870" />
					<criterion test_ref="wrt-97" negate="true" comment="the patch kb830352 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL733" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0823</cveid>
			<dates>
				<created date="2003-12-18"/>
				<modified date="2004-01-21">Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.</modified>
				<modified date="2004-03-04">Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CAN-2003-1027</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL743" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft FrontPage Server Extensions 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0822</cveid>
			<dates>
				<created date="2003-03-04"/>
				<modified date="2003-03-05">Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions 2000 and 2002 allows remote attackers to execute arbitrary code via a certain chunked encoded request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" />
					<criterion test_ref="wrt-88" negate="true" comment="the patch q810217 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL745" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1026</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.00.2737.800" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL751" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Microsoft Data Access Compnents 2.7</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2003-0903</cveid>
			<dates>
				<created date="2004-01-13"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-100" comment="MDAC 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists" />
					<criterion test_ref="wrt-110" negate="true" comment="the patch q832483 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL762" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SharePoint Team Services</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0824</cveid>
			<dates>
				<created date="2003-12-09"/>
				<modified date="2004-01-14">Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.</modified>
				<modified date="2004-09-14">XP SP2 added</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
			</dates>
			<description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request</description>
			<status>INTERIM</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-78" comment="Windows 2000, XP, or 2003 is installed" />
					<criterion test_ref="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-34" comment="SharePoint Team Services are enabled (2K, XP, 2003)" />
					<criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL774" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1026</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.00.2800.1400" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL775" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Microsoft Data Access Compnents 2.8</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2003-0903</cveid>
			<dates>
				<created date="2004-01-13"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-104" comment="MDAC 2.8 (RTM) is installed" />
					<criterion test_ref="wft-44" comment="the version of odbcbcp.dll is less than 2000.85.1025.0" />
					<criterion test_ref="wft-39" comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" />
					<criterion test_ref="cmp-103" comment="the patch q832483 is not installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL778" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0894</cveid>
			<dates>
				<created date="2004-12-28"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-328" comment="the version of lsasrv.dll is less than 5.0.2195.6987" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL779" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0112</cveid>
			<dates>
				<created date="2004-11-30"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-76" comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL794" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Windows Script Engine for JScript v5.1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0010</cveid>
			<dates>
				<created date="2004-03-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<modified date="2004-08-24">Added patch information to definition</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-120" comment="the version of jscript.dll is less than 5.1.0.8513" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
					<criterion test_ref="wrt-500" negate="true" comment="the patch js56nen.exe (5.1.0.8513 version) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-76" comment="active scripting is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL795" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Windows Script Engine for JScript v5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0010</cveid>
			<dates>
				<created date="2004-03-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<modified date="2004-08-24">Added patch information to definition</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-121" comment="the version of jscript.dll is less than 5.5.0.8513" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
					<criterion test_ref="wrt-501" negate="true" comment="the patch js56nen.exe (5.5.0.8513 version) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-76" comment="active scripting is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL796" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-0818</cveid>
			<dates>
				<created date="2004-02-12"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-108" comment="the version of msasn1.dll is less than 5.0.2195.6824" />
					<criterion test_ref="wrt-99" negate="true" comment="the patch kb828028 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL797" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0818</cveid>
			<dates>
				<created date="2004-02-12"/>
				<modified date="2004-09-13"></modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-53" comment="a vulnerable version of msasn1.dll exists" />
					<criterion test_ref="wrt-99" negate="true" comment="the patch kb828028 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL799" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-0818</cveid>
			<dates>
				<created date="2004-02-12"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-106" comment="the version of msasn1.dll is less than 5.2.3790.88" />
					<criterion test_ref="wrt-99" negate="true" comment="the patch kb828028 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL800" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CVE">2003-0825</cveid>
			<dates>
				<created date="2004-02-12"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-110" comment="the version of wins.exe is less than 4.0.1381.7255" />
					<criterion test_ref="wrt-97" negate="true" comment="the patch kb830352 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL801" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CVE">2003-0825</cveid>
			<dates>
				<created date="2004-02-12"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-111" comment="the version of wins.exe is less than 4.0.1381.33554" />
					<criterion test_ref="wrt-97" negate="true" comment="the patch kb830352 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL802" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CVE">2003-0825</cveid>
			<dates>
				<created date="2004-02-12"/>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-112" comment="the version of wins.exe is less than 5.2.3790.99" />
					<criterion test_ref="wrt-97" negate="true" comment="the patch kb830352 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL803" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>PWLib</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0097</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Added a program_name element to rlt-217</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-257" comment="pwlib version is less than 1.4.7-4.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-217" comment="a program is listening on TCP or UDP port 1720" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL804" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>netpbm</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2003-0924</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-341" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-342" comment="Vulnerable configuration" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL805" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2003-1026</cveid>
			<dates>
				<created date="2004-02-03"/>
				<modified date="2004-03-04">Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.00.3790.118" />
					<criterion test_ref="wrt-140" negate="true" comment="the patch q832894 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL806" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0083</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CAN-2004-0084 and CAN-2004-0106</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL807" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0084</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CAN-2004-0083 and CAN-2004-0106</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL809" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0106</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CAN-2004-0083 and CAN-2004-0084</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL810" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>netpbm</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2003-0924</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-574" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-342" comment="Vulnerable configuration" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL811" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mutt</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CVE">2004-0078</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-265" comment="mutt version is less than 1.4.1-3.3" />
				</software>
				<configuration>
					<criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL813" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mailman</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0965</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-266" comment="mailman version is less than 2.1.1-5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-218" comment="httpd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL815" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mailman</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0992</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-266" comment="mailman version is less than 2.1.1-5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-218" comment="httpd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL818" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Gaim</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0006</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-267" comment="gaim version is less than 0.75-0.9.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-802" comment="/usr/bin/gaim is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL819" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Gaim</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0007</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-267" comment="gaim version is less than 0.75-0.9.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-802" comment="/usr/bin/gaim is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL820" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Gaim</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0008</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-267" comment="gaim version is less than 0.75-0.9.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-802" comment="/usr/bin/gaim is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL821" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>slocate</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0848</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-268" comment="slocate version is less than 2.7-2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-805" comment="/usr/bin/slocate is setgid" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL822" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Midnight Commander</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-1023</cveid>
			<dates>
				<created date="2004-03-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-269" comment="mc version is less than 4.6.0-7.9" />
				</software>
				<configuration>
					<criterion test_ref="cmp-806" comment="/usr/bin/mc is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL823" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>KDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0592</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-270" comment="kdelibs version is less than 3.1-13" />
				</software>
				<configuration>
					<criterion test_ref="cmp-304" comment="/usr/bin/konqueror is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL825" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>mremap</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2004-0077</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-808" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL826" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>PWLib</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0097</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Added a program_name element to rlt-217</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-274" comment="pwlib version is less than 1.4.7-7.EL" />
				</software>
				<configuration>
					<criterion test_ref="rlt-217" comment="a program is listening on TCP or UDP port 1720" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL827" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Samba 3.0.0 and 3.0.1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2004-0082</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-275" comment="samba version is less than 3.0.2-6.3E" />
				</software>
				<configuration>
					<criterion test_ref="rlt-210" comment="smbd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL828" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>mod_python</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0973</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-276" comment="mod_python version is less than 3.0.1-4" />
				</software>
				<configuration>
					<criterion test_ref="rlt-220" comment="httpd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL830" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0083</cveid>
			<dates>
				<created date="2004-02-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CAN-2004-0084 and CAN-2004-0106</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-277" comment="XFree86 version is less than 4.3.0-55.EL" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL831" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0084</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CAN-2004-0083 and CAN-2004-0106</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-277" comment="XFree86 version is less than 4.3.0-55.EL" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL832" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0106</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CAN-2004-0083 and CAN-2004-0084</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-277" comment="XFree86 version is less than 4.3.0-55.EL" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL833" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>XMLSoft Libxml2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0110</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml2 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-815" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL834" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0003</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-816" comment="Vulnerable Configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL835" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0010</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-816" comment="Vulnerable Configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL836" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Vicam USB driver</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2004-0075</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-816" comment="Vulnerable Configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL837" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>mremap</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2004-0077</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-816" comment="Vulnerable Configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL838" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Mutt</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2004-0078</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-284" comment="mutt version is less than 1.4.1-3.4" />
				</software>
				<configuration>
					<criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL839" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>mod_python</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0973</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-276" comment="mod_python version is less than 3.0.1-4" />
				</software>
				<configuration>
					<criterion test_ref="rlt-220" comment="httpd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL842" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Media Services</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2003-0905</cveid>
			<dates>
				<created date="2004-03-09"/>
				<status_change date="2004-03-25">INTERIM</status_change>
			</dates>
			<description>Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets</description>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-59" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server" />
					<criterion test_ref="wft-46" comment="the version of nscm.exe is less than 4.1.0.3934" />
					<criterion test_ref="wft-47" comment="the version of nspmon.exe is less than 4.1.0.3934" />
					<criterion test_ref="wrt-149" negate="true" comment="the patch kb832359 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-3" negate="true" comment="configured to only offer streaming media over unicast" />
					<criterion test_ref="wrt-160" negate="true" comment="the Windows Media Station service is disabled" />
					<criterion test_ref="wrt-161" negate="true" comment="the Windows Media Monitor service is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL843" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Outlook</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2004-0121</cveid>
			<dates>
				<created date="2004-03-09"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-197" comment="Outlook 2002 is installed" />
					<criterion test_ref="wft-130" comment="the version of outlook.exe is less than 10.00.5709.0000" />
					<criterion test_ref="wrt-198" negate="true" comment="the patch kb828040 is installed" />
					<criterion test_ref="wrt-199" negate="true" comment="Microsoft Office XP Service Pack 3 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL844" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>MSN Messenger</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2004-0122</cveid>
			<dates>
				<created date="2004-03-09"/>
				<modified date="2004-03-30">Fixed the path for both versions of the file to look at the correct registry key to determine the location of the 'Program Files' folder..  </modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-68" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL845" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>gdk-pixbuf</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2004-0111</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-821" comment="Vulnerable configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL846" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>gdk-pixbuf</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2004-0111</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-822" comment="Vulnerable configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL847" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>tcpdump</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0989</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CAN-2004-0057</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-291" comment="tcpdump version is less than 3.7.2-7.9.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL849" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>sysstat</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0107</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CAN-2004-0108</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-292" comment="sysstat version is less than 4.0.7-4.rhl9.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL850" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>tcpdump</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0055</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-291" comment="tcpdump version is less than 3.7.2-7.9.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL851" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>tcpdump</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0057</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CAN-2003-0989</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-291" comment="tcpdump version is less than 3.7.2-7.9.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL852" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>tcpdump</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0989</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CAN-2004-0057</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-293" comment="tcpdump version is less than 3.7.2-7.E3.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL853" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>tcpdump</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0055</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-293" comment="tcpdump version is less than 3.7.2-7.E3.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL854" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>tcpdump</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0057</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CAN-2003-0989</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-293" comment="tcpdump version is less than 3.7.2-7.E3.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL855" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>CVS server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0977</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-294" comment="cvs version is less than 1.11.2-13" />
				</software>
				<configuration>
					<criterion test_ref="ret-974" comment="/ is world-writable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL856" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-1012</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-829" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-830" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL857" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Tethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-1013</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-829" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-830" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL858" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>KDE Personal Information Management (kdepim)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CVE">2003-0988</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-297" comment="kdepim version is less than 3.1-6" />
				</software>
				<configuration>
					<criterion test_ref="cmp-839" comment="/usr/share/services/kfile_vcf.desktop is readable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL859" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0984</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-840" comment="Vulnerable Configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL860" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2003-0985</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21 does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-840" comment="Vulnerable Configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL861" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>nfs-utils packages</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0154</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-301" comment="nfs-utils version is less than 1.0.6-7.EL" />
				</software>
				<configuration>
					<criterion test_ref="rlt-221" comment="rpc.mountd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL862" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Sysstat</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0107</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CAN-2004-0108</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-302" comment="sysstat version is less than 4.0.7-4.EL3.2" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL863" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>httpd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0542</cveid>
			<dates>
				<created date="2004-03-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-303" comment="httpd version is less than 2.0.40-21.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-203" comment="httpd.worker is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL864" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0542</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-304" comment="httpd version is less than 2.0.46-26.ent" />
				</software>
				<configuration>
					<criterion test_ref="rlt-203" comment="httpd.worker is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL865" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>KDE Personal Information Management (kdepim)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2003-0988</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-305" comment="kdepim version is less than 3.1.3-3.3" />
				</software>
				<configuration>
					<criterion test_ref="cmp-839" comment="/usr/share/services/kfile_vcf.desktop is readable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL866" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>CVS server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0977</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-306" comment="cvs version is less than 1.11.2-14" />
				</software>
				<configuration>
					<criterion test_ref="ret-974" comment="/ is world-writable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL867" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2003-0985</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21 does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-843" comment="Vulnerable Configuration" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL868" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2004-0001</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-207" comment="ix86 architecture" />
					<criterion test_ref="rvt-310" comment="kernel version is less than 2.4.21-9.EL" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL869" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Net-SNMP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2003-0935</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-311" comment="net-snmp version is less than 5.0.9-2.30E.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-223" comment="snmpd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL870" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0079</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-312" comment="openssl version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-313" comment="openssl-devel version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-314" comment="openssl-perl version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-315" comment="openssl096b version is less than 0.9.6b-16" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL871" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0081</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-312" comment="openssl version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-313" comment="openssl-devel version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-314" comment="openssl-perl version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-315" comment="openssl096b version is less than 0.9.6b-16" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL872" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0564</cveid>
			<dates>
				<created date="2004-03-18"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-316" comment="mozilla-nss version is less than 1.4.2-0.9.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL873" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0594</cveid>
			<dates>
				<created date="2004-03-18"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-317" comment="mozilla version is less than 1.4.2-0.9.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-844" comment="/usr/bin/mozilla is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL874" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2004-0191</cveid>
			<dates>
				<created date="2004-03-18"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-317" comment="mozilla version is less than 1.4.2-0.9.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-844" comment="/usr/bin/mozilla is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL875" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>libxml2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0110</cveid>
			<dates>
				<created date="2004-02-22"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml2 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-815" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL876" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>httpd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2004-0113</cveid>
			<dates>
				<created date="2004-03-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-323" comment="mod_ssl version is less than 2.0.46-32.ent" />
				</software>
				<configuration>
					<criterion test_ref="rlt-220" comment="httpd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL877" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Red Hat 9</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2004-0189</cveid>
			<dates>
				<created date="2004-04-07"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-325" comment="squid version is less than 2.5STABLE1-3.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-225" comment="squid is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL878" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Red Hat 9</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0176</cveid>
			<dates>
				<created date="2004-04-07"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-848" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL879" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Red Hat 9</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0365</cveid>
			<dates>
				<created date="2004-04-07"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-848" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL880" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Red Hat 9</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0367</cveid>
			<dates>
				<created date="2004-04-07"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-848" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL882" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2004-0380</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-170" comment="Outlook Express 5.5 SP2 is installed" />
					<criterion test_ref="wft-182" comment="the version of inetcomm.dll is less than 5.50.4939.300" />
					<criterion test_ref="wrt-188" negate="true" comment="the patch kb837009 is installed (installed components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL883" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0533</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-192" comment="the version of lsasrv.dll is less than 5.0.2195.6902" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL885" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Secure Sockets Layer (SSL)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2004-0120</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-172" comment="the version of schannel.dll is less than 5.2.3790.132" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL886" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Secure Sockets Layer (SSL)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0120</cveid>
			<dates>
				<created date="2004-04-13"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-130" comment="a vulnerable version of schannel.dll exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL887" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0176</cveid>
			<dates>
				<created date="2004-04-08"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-863" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL889" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Private Communications Transport (PCT)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0719</cveid>
			<dates>
				<created date="2004-04-13"/>
				<modified date="2004-09-13">added cmp-66</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-130" comment="a vulnerable version of schannel.dll exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
					<criterion test_ref="wrt-165" negate="true" comment="PCT support is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL890" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Local Descriptor Table (LDT)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
				<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
			</contributors>
			<cveid status="CAN">2003-0910</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-191" comment="the version of wintrust.dll is less than 5.131.2195.6824" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL891" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0365</cveid>
			<dates>
				<created date="2004-04-08"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-863" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL892" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Secure Sockets Layer (SSL)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2004-0120</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-171" comment="the version of schannel.dll is less than 5.1.2195.6899" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL893" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0813</cveid>
			<dates>
				<created date="2004-04-20"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CAN-2003-0352 (Blaster/Nachi), CAN-2003-0715, and CAN-2003-0528, and as demonstrated by certain exploits against those vulnerabilities</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-186" comment="the version of rpcrt4.dll is less than 5.0.2195.6904" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL894" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0813</cveid>
			<dates>
				<created date="2004-04-20"/>
			</dates>
			<description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CAN-2003-0352 (Blaster/Nachi), CAN-2003-0715, and CAN-2003-0528, and as demonstrated by certain exploits against those vulnerabilities</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-17" comment="a vulnerable version of rpcrt4.dll exists on Server 2003" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL895" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows logon process (winlogon)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0806</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-136" comment="a vulnerable version of msgina.dll exists on NT" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-196" comment="machine is a member of a domain" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL896" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows logon process (winlogon)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0806</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-133" comment="the version of msgina.dll is less than 5.1.2600.136" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-196" comment="machine is a member of a domain" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL897" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
				<product>Windows Metafile (WMF)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0906</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1allows remote attackers to execute arbitrary code via a malformed WNF or EMF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-89" comment="a vulnerable version of mf3216.dll exists on NT" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL898" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0533</cveid>
			<dates>
				<created date="2004-04-13"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-143" comment="a vulnerable version of lsasrv.dll exists on XP" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL900" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0813</cveid>
			<dates>
				<created date="2004-04-20"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CAN-2003-0352 (Blaster/Nachi), CAN-2003-0715, and CAN-2003-0528, and as demonstrated by certain exploits against those vulnerabilities</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-1" comment="a vulnerable version of rpcrt4.dll exists on XP" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL902" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0081</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-318" comment="openssl version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-319" comment="openssl-devel version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-320" comment="openssl-perl version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-321" comment="openssl096 version is less than 0.9.6-25.9" />
					<criterion test_ref="rvt-322" comment="openssl096b version is less than 0.9.6b-15" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL903" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Private Communications Transport (PCT)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0719</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-170" comment="the version of schannel.dll is less than 4.87.1964.1880" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
					<criterion test_ref="wrt-165" negate="true" comment="PCT support is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL904" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2003-0907</cveid>
			<dates>
				<created date="2004-04-14"/>
				<modified date="2004-05-12">Added a criterion to the configuration section to see if the HCP protocol is registered.</modified>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-303" comment="the version of helpctr.exe is less than 5.2.3790.125" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-12" negate="true" comment="the HCP Protocol is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL905" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0367</cveid>
			<dates>
				<created date="2004-04-08"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-863" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL907" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>H.323</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
				<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
			</contributors>
			<cveid status="CAN">2004-0117</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-150" comment="the version of h323.tsp is less than 5.0.2195.6901" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL909" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2001-0507</cveid>
			<dates>
				<created date="2004-05-04"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-304" comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL911" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Local Descriptor Table (LDT)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
				<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
			</contributors>
			<cveid status="CAN">2003-0910</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-190" comment="the version of wintrust.dll is less than 5.131.1880.14" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL912" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2001-0507</cveid>
			<dates>
				<created date="2004-05-04"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-305" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL913" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">1999-0278</cveid>
			<dates>
				<created date="2004-05-04"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-306" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" />
					<criterion test_ref="wrt-347" negate="true" comment="Service Pack 6 Installed (or later)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL914" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0564</cveid>
			<dates>
				<created date="2004-04-08"/>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-330" comment="mozilla-nss version is less than 1.4.2-3.0.2" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL915" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">1999-0874</cveid>
			<dates>
				<created date="2004-05-04"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-306" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" />
					<criterion test_ref="wrt-347" negate="true" comment="Service Pack 6 Installed (or later)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL917" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0594</cveid>
			<dates>
				<created date="2004-04-08"/>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-330" comment="mozilla-nss version is less than 1.4.2-3.0.2" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL919" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0533</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-157" comment="the version of lsasrv.dll is less than 5.2.3790.134" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL920" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 5.5, Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2001-0002</cveid>
			<dates>
				<created date="2004-04-29"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-901" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-307" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" />
					<criterion test_ref="wrt-351" negate="true" comment="Patch Q286045 Installed" />
					<criterion test_ref="wrt-352" negate="true" comment="Patch Q295106 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL921" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2001-0727</cveid>
			<dates>
				<created date="2004-04-29"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-308" comment="the version of mshtml.dll is less than 6.0.2712.0300" />
					<criterion test_ref="wrt-354" negate="true" comment="Patch Q313675 Installed" />
					<criterion test_ref="wrt-355" negate="true" comment="Patch Q316059.exe Installed" />
					<criterion test_ref="wrt-356" negate="true" comment="Patch Q319282 Installed" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-902" comment="File Downloads Not Disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL922" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2003-0344</cveid>
			<dates>
				<created date="2004-04-29"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL923" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-0190</cveid>
			<dates>
				<created date="2004-04-30"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-310" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL924" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2004-0123</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-194" comment="the version of msasn1.dll is less than 5.2.3790.139" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL925" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-0022</cveid>
			<dates>
				<created date="2004-04-29"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-311" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-355" negate="true" comment="Patch Q316059.exe Installed" />
					<criterion test_ref="wrt-356" negate="true" comment="Patch Q319282 Installed" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-903" comment="Run ActiveX Controls and Plugins Not Disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL926" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2003-0113</cveid>
			<dates>
				<created date="2004-04-30"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wft-312" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL927" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2000-0778</cveid>
			<dates>
				<created date="2004-05-04"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL928" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0112</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-312" comment="openssl version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-313" comment="openssl-devel version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-314" comment="openssl-perl version is less than 0.9.7a-33.4" />
					<criterion test_ref="rvt-315" comment="openssl096b version is less than 0.9.6b-16" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL929" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2002-0869</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-329" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL930" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2002-0869</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL931" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2002-1180</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL932" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">1999-0736</cveid>
			<dates>
				<created date="2004-05-17"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-331" comment="File %windir%\System32\code.asp is less than 4.0.1381.279" />
					<criterion test_ref="wrt-386" negate="true" comment="Patch Q232449 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL933" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0226</cveid>
			<dates>
				<created date="2004-05-17"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-332" comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" />
					<criterion test_ref="wrt-387" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL936" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0227</cveid>
			<dates>
				<created date="2004-05-18"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-333" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" />
					<criterion test_ref="wrt-388" negate="true" comment="Patch KB817772 Installed" />
					<criterion test_ref="wrt-389" negate="true" comment="Patch KB822343 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL937" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2004-0191</cveid>
			<dates>
				<created date="2004-04-08"/>
				<modified date="2004-05-11">Corrected pattern used in rrt-206</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-330" comment="mozilla-nss version is less than 1.4.2-3.0.2" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL938" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0349</cveid>
			<dates>
				<created date="2004-05-18"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-334" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" />
					<criterion test_ref="wrt-389" negate="true" comment="Patch KB822343 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL939" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0424</cveid>
			<dates>
				<created date="2004-05-10"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or executee arbitrary code via the MCAST_MSFILTER socket option</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-921" comment="kernel versions" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL940" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0109</cveid>
			<dates>
				<created date="2004-05-10"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x , allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-921" comment="kernel versions" />
				</software>
				<configuration>
					<criterion test_ref="cmp-923" comment="/bin/mount is world-executable AND Set-UID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL941" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2004-0189</cveid>
			<dates>
				<created date="2004-05-10"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-337" comment="squid version is less than 2.5.STABLE3-5.3E" />
				</software>
				<configuration>
					<criterion test_ref="rlt-225" comment="squid is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL942" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2002-1181</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL944" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2002-1181</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-329" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL945" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0155</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-338" comment="ipsec-tools version is less than 0.2.5-0.4" />
				</software>
				<configuration>
					<criterion test_ref="rlt-230" comment="racoon is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL946" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>H.323</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
				<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
			</contributors>
			<cveid status="CAN">2004-0117</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-151" comment="the version of h323.tsp is less than 5.2.3790.132" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL947" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0164</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-338" comment="ipsec-tools version is less than 0.2.5-0.4" />
				</software>
				<configuration>
					<criterion test_ref="rlt-230" comment="racoon is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL948" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2003-0309</cveid>
			<dates>
				<created date="2004-04-29"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL951" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Private Communications Transport (PCT)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0719</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-171" comment="the version of schannel.dll is less than 5.1.2195.6899" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
					<criterion test_ref="wrt-165" negate="true" comment="PCT support is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL952" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>SNMP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">1999-0815</cveid>
			<dates>
				<created date="2004-05-04"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-313" comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" />
					<criterion test_ref="wrt-373" negate="true" comment="Windows NT Service Pack 5 (or later) installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL954" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0411</cveid>
			<dates>
				<created date="2004-05-19"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-339" comment="kdelibs version is less than 3.1.3-6.4" />
				</software>
				<configuration>
					<criterion test_ref="cmp-924" comment="telnet, rlogin, ssh or kmail is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL955" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0116</cveid>
			<dates>
				<created date="2004-04-20"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-189" comment="the version of rpcss.dll is less than 5.0.2195.6906" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL956" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1041</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CAN-2004-0475</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1071" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL957" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0116</cveid>
			<dates>
				<created date="2004-04-20"/>
			</dates>
			<description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-16" comment="a vulnerable version of rpcss.dll exists on Server 2003" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL958" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0116</cveid>
			<dates>
				<created date="2004-04-20"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-10" comment="a vulnerable version of rpcss.dll exists on XP" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-283" comment="DCOM is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL959" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
				<product>Windows Metafile (WMF)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0906</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1allows remote attackers to execute arbitrary code via a malformed WNF or EMF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-138" comment="the version of mf3216.dll is less than 5.0.2195.6898" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL961" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Data Access Components 2.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0353</cveid>
			<dates>
				<created date="2004-05-04"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-904" comment="Affected MDAC versions" />
					<criterion test_ref="wrt-376" negate="true" comment="Patch Q823718 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL962" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Data Access Components 2.6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0353</cveid>
			<dates>
				<created date="2004-05-04"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-377" comment="DataAccess Installed" />
					<criterion test_ref="wft-315" comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" />
					<criterion test_ref="wrt-376" negate="true" comment="Patch Q823718 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL963" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2003-0114</cveid>
			<dates>
				<created date="2004-04-30"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL964" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>H.323</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
				<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
			</contributors>
			<cveid status="CAN">2004-0117</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-160" comment="a vulnerable version of h323.tsp exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL966" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0227</cveid>
			<dates>
				<created date="2004-05-18"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-335" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" />
					<criterion test_ref="wrt-388" negate="true" comment="Patch KB817772 Installed" />
					<criterion test_ref="wrt-389" negate="true" comment="Patch KB822343 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL967" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0426</cveid>
			<dates>
				<created date="2004-05-19"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-340" comment="rsync version is less than 2.5.7-4.3E" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL968" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Microsoft Jet Database Engine</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2004-0197</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-140" comment="a vulnerable version of Microsoft Jet 4.0 is installed" />
					<criterion test_ref="wrt-185" negate="true" comment="the patch kb837001 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL969" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0807</cveid>
			<dates>
				<created date="2004-05-25"/>
				<status_change date="2004-06-18">INTERIM</status_change>
				<status_change date="2004-07-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a specially crafted request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-8" comment="Windows NT 4.0 Server or Terminal Server is installed" />
					<criterion test_ref="cmp-21" comment="a vulnerable version of rpcproxy.dll exists on NT" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-385" comment="COM Internet Services are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL970" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0396</cveid>
			<dates>
				<created date="2004-05-20"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-341" comment="cvs version is less than 1.11.2-22" />
				</software>
				<configuration>
					<criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL971" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0421</cveid>
			<dates>
				<created date="2004-05-20"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-932" comment="libpng/libpng-devel is less than 1.2.2-21 or libpng10/libpng-devel less than 1.0.13 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL972" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0183</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-353" comment="tcpdump version is less than 3.7.2-7.E3.2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-1017" comment="/usr/sbin/tcpdump is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL974" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-0027</cveid>
			<dates>
				<created date="2004-04-29"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-311" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-355" negate="true" comment="Patch Q316059.exe Installed" />
					<criterion test_ref="wrt-356" negate="true" comment="Patch Q319282 Installed" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL975" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0079</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-318" comment="openssl version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-319" comment="openssl-devel version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-320" comment="openssl-perl version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-321" comment="openssl096 version is less than 0.9.6-25.9" />
					<criterion test_ref="rvt-322" comment="openssl096b version is less than 0.9.6b-15" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL976" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0184</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-353" comment="tcpdump version is less than 3.7.2-7.E3.2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-1017" comment="/usr/sbin/tcpdump is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL977" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0234</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14 allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-354" comment="lha version is less than 1.14i-10.2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-1019" comment="/usr/bin/lha is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL978" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0235</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path")</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-354" comment="lha version is less than 1.14i-10.2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-1019" comment="/usr/bin/lha is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL979" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0233</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-355" comment="utempter version is less than 0.5.5-1.3EL.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-1020" comment="/usr/sbin/utempter is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL980" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0541</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-356" comment="squid version is less than 2.5.STABLE3-6.3E" />
				</software>
				<configuration>
					<criterion test_ref="rlt-233" comment="squid is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL982" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0504</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="cmp-1022" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL983" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>IIS 5.1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2002-0869</cveid>
			<dates>
				<created date="2004-05-19"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-390" comment="IIS 5.1 Minor Version" />
					<criterion test_ref="wft-336" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL984" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0403</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-338" comment="ipsec-tools version is less than 0.2.5-0.4" />
				</software>
				<configuration>
					<criterion test_ref="rlt-230" comment="racoon is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL986" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0505</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="cmp-1022" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL987" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0506</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="cmp-1022" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL988" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0507</cveid>
			<dates>
				<created date="2004-06-10"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="cmp-1022" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-849" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL990" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2004-0380</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-171" comment="Outlook Express 6 is installed" />
					<criterion test_ref="wft-183" comment="the version of inetcomm.dll is less than 6.00.2739.300" />
					<criterion test_ref="wrt-188" negate="true" comment="the patch kb837009 is installed (installed components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL991" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>MIT Kerberos 5 (krb5)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0523</cveid>
			<dates>
				<created date="2004-06-29"/>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-361" comment="krb5-libs rpm version prior to 1.2.7-24 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL993" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>CVS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0414</cveid>
			<dates>
				<created date="2004-06-29"/>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL994" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>CVS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0416</cveid>
			<dates>
				<created date="2004-06-29"/>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL995" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0807</cveid>
			<dates>
				<created date="2004-05-25"/>
				<status_change date="2004-06-18">INTERIM</status_change>
				<status_change date="2004-07-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a specially crafted request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-289" comment="the version of rpcproxy.dll is less than 5.0.2195.6904" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-385" comment="COM Internet Services are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL996" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>File and Print Sharing</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2000-0979</cveid>
			<dates>
				<created date="2004-05-18"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-391" comment="Windows 98 Installed" />
					<criterion test_ref="wft-337" comment="File %windir%\system\vserver.vxd version is less than 4.10.2001" />
					<criterion test_ref="wrt-392" negate="true" comment="Patch 273991USA8.EXE Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL997" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0461</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-346" comment="kernel version is less than 2.4.21-15.EL" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ret-1024" comment="/proc/tty/driver/serial is world-readable" />
					<criterion test_ref="ret-1025" comment="/proc/tty/driver/ is world-executable" />
					<criterion test_ref="ret-1026" comment="/proc/tty/ is world-executable" />
					<criterion test_ref="ret-1027" comment="/proc/ is world-executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1000" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0907</cveid>
			<dates>
				<created date="2004-04-14"/>
				<modified date="2004-05-12">Added a criterion to the configuration section to see if the HCP protocol is registered.</modified>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-905" comment="a vulnerable version of helpctr.exe exists on XP" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-12" negate="true" comment="the HCP Protocol is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1001" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>CVS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0417</cveid>
			<dates>
				<created date="2004-06-29"/>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1003" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>CVS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0418</cveid>
			<dates>
				<created date="2004-06-29"/>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1004" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows XP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0909</cveid>
			<dates>
				<created date="2004-04-14"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-908" comment="A vulnerable version of evtgprov.dll exists on XP" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1006" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>SquirrelMail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0519</cveid>
			<dates>
				<created date="2004-06-29"/>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-11">ACCEPTED</status_change>
			</dates>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-363" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" />
					<criterion test_ref="rrt-217" comment="php rpm is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="rlt-218" comment="httpd is listening on the network" />
					<criterion test_ref="rft-1" comment="/etc/httpd/modules/libphp4.so exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1007" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0123</cveid>
			<dates>
				<created date="2004-04-13"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-150" comment="a vulnerable version of msasn1.dll exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1008" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0199</cveid>
			<dates>
				<created date="2004-05-12"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm)</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-114" comment="a vulnerable version of helpctr.exe exists on XP" />
					<criterion test_ref="wrt-10" negate="true" comment="the patch kb840374 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-12" negate="true" comment="the HCP Protocol is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1009" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>IIS 5.1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2002-1182</cveid>
			<dates>
				<created date="2004-05-19"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-390" comment="IIS 5.1 Minor Version" />
					<criterion test_ref="wft-336" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1010" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2004-0380</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-173" comment="Outlook Express 6 SP1 is installed" />
					<criterion test_ref="wft-185" comment="the version of inetcomm.dll is less than 6.00.2800.1409" />
					<criterion test_ref="wrt-188" negate="true" comment="the patch kb837009 is installed (installed components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1011" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2002-1182</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1012" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>SquirrelMail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0520</cveid>
			<dates>
				<created date="2004-06-29"/>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-11">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-363" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" />
					<criterion test_ref="rrt-217" comment="php rpm is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="rlt-218" comment="httpd is listening on the network" />
					<criterion test_ref="rft-1" comment="/etc/httpd/modules/libphp4.so exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1013" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0984</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-346" comment="kernel version is less than 2.4.21-15.EL" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1014" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2001-0875</cveid>
			<dates>
				<created date="2004-04-29"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-353" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-308" comment="the version of mshtml.dll is less than 6.0.2712.0300" />
					<criterion test_ref="wrt-354" negate="true" comment="Patch Q313675 Installed" />
					<criterion test_ref="wrt-355" negate="true" comment="Patch Q316059.exe Installed" />
					<criterion test_ref="wrt-356" negate="true" comment="Patch Q319282 Installed" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-902" comment="File Downloads Not Disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1016" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Lightweight Directory Access Protocol (LDAP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2003-0663</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" />
					<criterion test_ref="wft-192" comment="the version of lsasrv.dll is less than 5.0.2195.6902" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1017" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0003</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-347" comment="kernel version is less than 2.4.21-15.EL" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1018" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2001-0333</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-338" comment="File %windir%\System32\w3svc.dll is less than 4.2.764.1" />
					<criterion test_ref="wrt-241" negate="true" comment="Patch Q295534 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1021" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2000-0377</cveid>
			<dates>
				<created date="2004-06-03"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1043" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1044" comment="For Terminal Server" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1022" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Exchange 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0049</cveid>
			<dates>
				<created date="2004-06-03"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-457" comment="Microsoft Exchange 2000 Installed" />
					<criterion test_ref="wft-417" comment="File %ExchangeInstallDir%\bin\mad.exe is less than 6.0.5770.21" />
					<criterion test_ref="wrt-458" negate="true" comment="Patch Q316056 installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-459" comment="Everyone group given remote access permissions" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1023" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">1999-0562</cveid>
			<dates>
				<created date="2004-06-03"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The registry in Windows NT can be accessed remotely by users who are not administrators</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-399" comment="Remote access to registry not controlled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1024" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>NetBIOS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">1999-0621</cveid>
			<dates>
				<created date="2004-05-18"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>A component service related to NETBIOS is running</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="cmp-933" comment="Windows NT or 2000 Installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-934" comment="NetBIOS enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1025" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0642</cveid>
			<dates>
				<created date="2004-06-15"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-460" comment="SQL Server 2000 installed" />
					<criterion test_ref="wft-418" comment="the version of sqlservr.exe is less than 2000.80.650.0" />
					<criterion test_ref="wft-419" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-428" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-429" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-430" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-431" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-420" comment="the version of xpstar.dll is less than 2000.80.628.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1027" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft DirectPlay</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0202</cveid>
			<dates>
				<created date="2004-06-11"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="cmp-1045" comment="Vulnerable versions of DirectX" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1028" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2004-0380</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" />
					<criterion test_ref="wft-184" comment="the version of inetcomm.dll is less than 6.00.3790.137" />
					<criterion test_ref="wrt-186" negate="true" comment="the patch kb837009 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1030" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>COM Internet Services</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0807</cveid>
			<dates>
				<created date="2004-05-25"/>
				<status_change date="2004-06-18">INTERIM</status_change>
				<status_change date="2004-07-02">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a specially crafted request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-193" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed" />
					<criterion test_ref="cmp-190" comment="a vulnerable version of rpcproxy.dll exists on Server 2003" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-385" comment="COM Internet Services are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1032" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Help and Support Center (HSC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2004-0199</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-294" comment="the version of helpctr.exe is less than 5.2.3790.161" />
					<criterion test_ref="wrt-10" negate="true" comment="the patch kb840374 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-12" negate="true" comment="the HCP Protocol is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1033" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>SquirrelMail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0521</cveid>
			<dates>
				<created date="2004-06-29"/>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-11">ACCEPTED</status_change>
			</dates>
			<description>SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rvt-363" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" />
					<criterion test_ref="rrt-217" comment="php rpm is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="rlt-218" comment="httpd is listening on the network" />
					<criterion test_ref="rft-1" comment="/etc/httpd/modules/libphp4.so exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1035" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0010</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-347" comment="kernel version is less than 2.4.21-15.EL" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1036" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Veritas Backup Exec 8.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-1117</cveid>
			<dates>
				<created date="2004-06-15"/>
				<status_change date="2004-06-30">INTERIM</status_change>
			</dates>
			<description>Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares</description>
			<status>INTERIM</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="ukn-25" comment="Affected bkupexec.exe versions 3.60.1.298" />
					<criterion test_ref="wrt-472" comment="Veritas Backup Exec 8.5 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-471" comment="RestrictAnonymous registry value allows anonymous connections" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1039" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Data Access Components 2.7</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0353</cveid>
			<dates>
				<created date="2004-05-04"/>
				<modified date="2004-07-20">Changed patch registry key value to IsInstalled</modified>
				<status_change date="2004-07-21">INTERIM</status_change>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-912" comment="Affected MDAC versions" />
					<criterion test_ref="wrt-376" negate="true" comment="Patch Q823718 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1041" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0124</cveid>
			<dates>
				<created date="2004-04-19"/>
				<status_change date="2004-04-20">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-195" comment="a vulnerable version of ole32.dll exists on NT" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1042" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0180</cveid>
			<dates>
				<created date="2004-05-10"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CAN-2004-0405</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-348" comment="cvs version is less than 1.11.2-18" />
				</software>
				<configuration>
					<criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1046" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Utility Manager</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2003-0908</cveid>
			<dates>
				<created date="2004-04-14"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CAN-2004-0213</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-322" comment="the version of umandlg.dll is less than 1.0.0.4" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1049" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matt Busby</submitter>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0112</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-318" comment="openssl version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-319" comment="openssl-devel version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-320" comment="openssl-perl version is less than 0.9.7a-20" />
					<criterion test_ref="rvt-321" comment="openssl096 version is less than 0.9.6-25.9" />
					<criterion test_ref="rvt-322" comment="openssl096b version is less than 0.9.6b-15" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1051" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2001-0333</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-339" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1053" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Compressed Folders</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2004-0575</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-14">Restructured the test to Windows XP at all service pack levels, but only on 32-bit architectures</modified>
				<modified date="2004-10-14">Added test for patch NOT installed</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1141" comment="vulnerable 32-bit version of zipfldr.dll" />
					<criterion test_ref="wrt-553" negate="true" comment="the patch q873376 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-554" negate="true" comment="Compressed Folders with zipfldr.dll are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1054" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows logon process (winlogon)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0806</cveid>
			<dates>
				<created date="2004-04-13"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-120" comment="a vulnerable version of msgina.dll exists" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-196" comment="machine is a member of a domain" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1056" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2002-0862</cveid>
			<dates>
				<created date="2004-07-12"/>
				<modified date="2004-07-13">Added superceding patch info.</modified>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-432" comment="the version of crypt32.dll is less than 5.131.2600.1123" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1059" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2002-1183</cveid>
			<dates>
				<created date="2004-07-12"/>
				<modified date="2004-07-13">Added superceding patch info.</modified>
				<modified date="2004-07-14">Changed to DRAFT</modified>
				<modified date="2004-07-20"></modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1060" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0405</cveid>
			<dates>
				<created date="2004-05-10"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CAN-2004-0180</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-348" comment="cvs version is less than 1.11.2-18" />
				</software>
				<configuration>
					<criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1062" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0124</cveid>
			<dates>
				<created date="2004-04-20"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-177" comment="the version of comsvcs.dll is less than 2000.2.3511.0" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1064" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
				<product>Windows Metafile (WMF)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0906</cveid>
			<dates>
				<created date="2004-04-13"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1allows remote attackers to execute arbitrary code via a malformed WNF or EMF image</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-170" comment="a vulnerable version of mf3216.dll exists on XP" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1065" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Red Hat Enteprise Linux 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0179</cveid>
			<dates>
				<created date="2004-05-10"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, or (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-349" comment="openoffice version is less than 1.1.0-15.EL" />
				</software>
				<configuration>
					<criterion test_ref="cmp-937" comment="OpenOffice Permissions" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1066" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0124</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-179" comment="the version of comsvcs.dll is less than 2001.12.4720.130" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1068" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2001-0241</cveid>
			<dates>
				<created date="2004-05-12"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-340" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1072" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0124</cveid>
			<dates>
				<created date="2004-04-20"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-178" comment="the version of comsvcs.dll is less than 2001.12.4414.53" />
					<criterion test_ref="wrt-189" negate="true" comment="the patch kb828741 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1076" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft ASN.1 Library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2004-0123</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-139" comment="Windows NT or 2000 is installed" />
					<criterion test_ref="wft-193" comment="the version of msasn1.dll is less than 5.0.2195.6905" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1077" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2002-0649</cveid>
			<dates>
				<created date="2004-06-15"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in SQL Server 2000 Resolution Service allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-460" comment="SQL Server 2000 installed" />
					<criterion test_ref="wft-426" comment="the version of sqlservr.exe is less than 2000.80.636.0" />
					<criterion test_ref="wft-427" comment="the version of ssnetlib.dll is less than 2000.80.636.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1079" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>NetBIOS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2000-1079</cveid>
			<dates>
				<created date="2004-05-18"/>
				<status_change date="2004-06-16">INTERIM</status_change>
				<status_change date="2004-06-30">ACCEPTED</status_change>
			</dates>
			<description>Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-943" comment="Windows 95, 98, NT or 2000 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-397" comment="TCP/IP NetBIOS not disabled" />
					<criterion test_ref="wrt-398" comment="WINS Client binding not disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1093" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Private Communications Transport (PCT)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-0719</cveid>
			<dates>
				<created date="2004-04-13"/>
				<status_change date="2004-05-05">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-172" comment="the version of schannel.dll is less than 5.2.3790.132" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-5" comment="SSL is enabled" />
					<criterion test_ref="wrt-165" negate="true" comment="PCT support is disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1094" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2003-0233</cveid>
			<dates>
				<created date="2004-04-30"/>
				<modified date="2004-09-22">Replaced IE cumulative patch IDs to correspond to the original IDs</modified>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CAN-2003-0115</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="wrt-141" negate="true" comment="the patch q832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1096" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 5.5, Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2001-0339</cveid>
			<dates>
				<created date="2004-04-29"/>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-901" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-323" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" />
					<criterion test_ref="wft-324" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" />
					<criterion test_ref="wrt-352" negate="true" comment="Patch Q295106 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1099" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2002-0677</cveid>
			<dates>
				<created date="2004-10-15"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-6" comment="Toolktalk installed" />
					<criterion test_ref="spt-255" negate="true" comment="Patch 112808-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1105" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>GDI+</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-20"/>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-413" comment="Windows XP or Windows Server 2003 is installed" />
					<criterion test_ref="wft-493" comment="the version of sxs.dll is less than 5.2.3790.121" />
					<criterion test_ref="wrt-512" negate="true" comment="the patch KB833987 is installed (for Windows Server 2003)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1133" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0549</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifiying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-267" comment="the version of mshtml.dll is less than 6.00.2800.1458" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1157" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Crystal Enterprise</product>
				<product>Crystal Reports</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0204</cveid>
			<dates>
				<created date="2004-06-09"/>
			</dates>
			<description>Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-341" comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-400" comment="the w3svc service is enabled" />
					<criterion test_ref="ukn-24" comment="a website linked to the Crystal Reports Viewer is active" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1168" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0571</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CAN-2004-090</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1186" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-1041</cveid>
			<dates>
				<created date="2004-07-13"/>
				<modified date="2004-07-14">added the unregistered HTML Help criterion to the configuration section of the criteria</modified>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CAN-2004-0475</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1241" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0901</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-326" comment="the version of mswrd632.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1273" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Sadmin</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0722</cveid>
			<dates>
				<created date="2004-10-15"/>
				<modified date="2004-10-15">Added check for sadmind called with strong authentication</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-7" comment="System and Network Administration Framework Installed" />
					<criterion test_ref="spt-259" negate="true" comment="Patch 116457-02 or later installed" />
					<criterion test_ref="spt-260" negate="true" comment="Patch 116442-01 or later installed" />
					<criterion test_ref="spt-261" negate="true" comment="Patch 116454-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="sit-209" comment="inetd.conf contains sadmind" />
					<criterion test_ref="sit-210" negate="true" comment="Sadmin called using strong authentication" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1279" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wrt-391" comment="Windows 98 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1294" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Internet Explorer 6</product>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CVE">2004-1050</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utili</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" />
					<criterion test_ref="cmp-25" negate="true" comment="patch kb889293 is installed (hotfix or ID)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1321" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0893</cveid>
			<dates>
				<created date="2004-12-16"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-146" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7268" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1330" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>IIS 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2003-0718</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1107" comment="Windows 2000 (sp5 or earlier) is installed" />
					<criterion test_ref="wft-501" comment="the version of httpext.dll is less than 5.0.2195.6958" />
					<criterion test_ref="wrt-549" negate="true" comment="the patch KB824151 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-541" negate="true" comment="WebDav is disabled(for iis 5.0)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1332" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2002-0862</cveid>
			<dates>
				<created date="2004-07-12"/>
				<modified date="2004-07-13">Added superceding patch info.</modified>
				<modified date="2004-07-14">Changed to DRAFT</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-215" comment="Windows 2000 Service Pack 4 (or later) is installed" />
					<criterion test_ref="wft-433" comment="the version of cryptdlg.dll is less than 5.0.1558.6608" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1344" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0212</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-347" comment="Service Pack 6 Installed (or later)" />
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-457" comment="the version of mstask.dll is less than 4.71.1979.1" />
					<criterion test_ref="wrt-492" negate="true" comment="Patch IE-KB841873-WindowsNT4sp6-x86-ENU.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1347" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>FreeRADIUS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0938</cveid>
			<dates>
				<created date="2004-11-22"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rvt-2" comment="FreeRADIUS rpm older than 1.0.1-1" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="rlt-5" comment="radiusd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1417" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0571</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CAN-2004-090</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1427" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>IIS 5.1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2003-0718</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-1110" comment="a vulnerable version of httpext.dll exists" />
					<criterion test_ref="wrt-549" negate="true" comment="the patch KB824151 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1436" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0368</cveid>
			<dates>
				<created date="2004-10-12"/>
				<modified date="2004-10-12">Added patch 107180-31 test for Solaris 7.  Changed vulnerable software test logic a little</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in dtlogin in CDE on Solaris, HP-UX, and possibly other operating systems, allows remote attackers to execute arbitrary code via a certain UDP packet</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sft-219" comment="File /usr/dt/bin/dtlogin exists" />
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-231" comment="Patch 108919-21 or later installed" />
					<criterion test_ref="spt-232" comment="Patch 112807-09 or later installed" />
					<criterion test_ref="spt-249" comment="Patch 107180-31 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-206" comment="dtlogin running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1455" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2002-1183</cveid>
			<dates>
				<created date="2004-07-12"/>
				<modified date="2004-07-13">Added superceding patch info.</modified>
				<modified date="2004-07-14">Changed to DRAFT</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862)</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1503" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2004-0201</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CAN-2003-1041</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1512" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>VDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0118</cveid>
			<dates>
				<created date="2004-06-11"/>
				<modified date="2004-07-19"></modified>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-342" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-933" comment="Windows NT or 2000 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1530" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0201</cveid>
			<dates>
				<created date="2004-07-13"/>
				<modified date="2004-07-14">added the unregistered HTML Help criterion to the configuration section of the criteria</modified>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CAN-2003-1041</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1549" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CAN">2004-1080</cveid>
			<dates>
				<created date="2005-01-03"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 4</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
					<criterion test_ref="wft-350" comment="the version of wins.exe is less than 5.2.3790.239" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1561" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0893</cveid>
			<dates>
				<created date="2004-12-16"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wft-148" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1563" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0839</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html"</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1581" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0893</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1601" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0214</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wrt-550" comment="Windows ME Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1655" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0901</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
					<criterion test_ref="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1718" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>VDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0118</cveid>
			<dates>
				<created date="2004-06-11"/>
				<status_change date="2004-08-04">ACCEPTED</status_change>
			</dates>
			<description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-1085" comment="Version check of Ntoskrnl for NT Terminal Server or NT Workstation" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1721" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Visual Studio .NET 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-24"/>
				<modified date="2004-09-30">changed affected platforms</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-519" comment="Microsoft Visual Studio .NET 2003 Installed" />
					<criterion test_ref="wrt-518" negate="true" comment="The patch KB830348 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1749" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0214</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1124" comment="a vulnerable version of shell32.dll exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1751" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>VDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0208</cveid>
			<dates>
				<created date="2004-10-13"/>
				<modified date="2004-10-13">fixed OS </modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" />
					<criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1781" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Task Scheduler</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0212</cveid>
			<dates>
				<created date="2004-07-14"/>
				<modified date="2004-09-14"></modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-455" comment="the version of mstask.dll is less than 5.1.2600.1555" />
					<criterion test_ref="wrt-483" negate="true" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" />
					<criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1793" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1048</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.00.2743.600" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1808" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Negotiate SSP interface</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0119</cveid>
			<dates>
				<created date="2004-06-14"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="wft-345" comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" />
				</software>
				<configuration>
					<criterion test_ref="wmt-206" comment="Negotiate is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1837" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1133" comment="a vulnerable version of grpconv.exe exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1843" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1136" comment="a vulnerable version of grpconv.exe exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1844" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>NIS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2001-1328</cveid>
			<dates>
				<created date="2004-12-29"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" />
					<criterion test_ref="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" />
					<criterion test_ref="spt-8" negate="true" comment="Patch 108750-02 or later installed" />
					<criterion test_ref="spt-9" negate="true" comment="Patch 110322-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-2" comment="ypbind running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1852" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>NetDDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0206</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-520" comment="the version of nddenb32.dll is less than 4.0.1381.33565" />
					<criterion test_ref="wft-521" comment="the version of netdde.exe is less than 4.0.1381.33574" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1872" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0209</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-535" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1886" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0893</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-154" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1888" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0894</cveid>
			<dates>
				<created date="2005-01-04"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
					<criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1943" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1041</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CAN-2004-0475</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1950" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0215</cveid>
			<dates>
				<created date="2004-08-26"/>
				<status_change date="2004-08-26">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-173" comment="Outlook Express 6 SP1 is installed" />
					<criterion test_ref="wft-467" comment="the version of inetcomm.dll is less than 6.0.2800.1441" />
					<criterion test_ref="wrt-494" negate="true" comment="the patch kb823353 is installed " />
				</software>
				<configuration>
					<criterion test_ref="wrt-495" negate="true" comment="all users have the preview pane disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1959" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0571</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CAN-2004-090</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-123" comment="the version of wordpad.exe is less than 5.1.2600.1606" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1962" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0119</cveid>
			<dates>
				<created date="2004-06-15"/>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="cmp-952" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and 64-bit or 32-bit version of Windows is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-206" comment="Negotiate is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1964" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Task Scheduler</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0212</cveid>
			<dates>
				<created date="2004-07-13"/>
				<modified date="2004-07-14">added compound tests</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="cmp-1070" comment="Affected mstask.dll file versions based on service pack levels" />
					<criterion test_ref="wrt-483" negate="true" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1976" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0571</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CAN-2004-090</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1982" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0174</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-18">Changed apache test to file test</modified>
				<modified date="2004-10-19">Changed apache test to package test</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Apache before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="spt-254" negate="true" comment="Patch 113146-05 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1997" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Negotiate SSP interface</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0119</cveid>
			<dates>
				<created date="2004-06-15"/>
				<modified date="2004-07-19"></modified>
				<modified date="2004-07-20"></modified>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-08-11">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
					<criterion test_ref="cmp-1095" comment="Version checks on XP for Ipnathlp.dll" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-206" comment="Negotiate is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2002" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0523</cveid>
			<dates>
				<created date="2004-10-11"/>
				<status_change date="2004-10-13">DRAFT</status_change>
			</dates>
			<description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-246" negate="true" comment="Patch 112908-16 or later installed" />
					<criterion test_ref="spt-247" negate="true" comment="Patch 112536-05 or later installed" />
					<criterion test_ref="cmp-1104" negate="true" comment="Patches 112237-11 and 112390-09 or greater installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-33" comment="System is configured to use kerberos" />
					<criterion test_ref="ukn-37" comment="Solaris Kerberos explicit or rules-based mapping" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2008" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0893</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-154" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
					<criterion test_ref="cmp-1112" comment="Windows XP 64-bit" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2011" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Bind</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0914</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-270" negate="true" comment="Patch 106938-08 or later installed" />
					<criterion test_ref="spt-271" negate="true" comment="Patch 109326-13 or later installed" />
					<criterion test_ref="spt-272" negate="true" comment="Patch 112970-06 or later installed" />
					<criterion test_ref="sat-10" comment="Core Solaris (SUNWcsu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-211" comment="in.named running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2016" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0203</cveid>
			<dates>
				<created date="2004-08-25"/>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-504" comment="Exchange 5.5 with SP4 Installed" />
					<criterion test_ref="wft-485" comment="the version of cdo.dll is less than 5.5.2558.10" />
					<criterion test_ref="wrt-505" negate="true" comment="the  patch kb842436 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-506" comment="Outlook Web Access exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2022" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0112</cveid>
			<dates>
				<created date="2004-07-13"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2025" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>login</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2001-0797</cveid>
			<dates>
				<created date="2004-12-29"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" />
					<criterion test_ref="spt-6" negate="true" comment="Patch 112300-01 or later installed" />
					<criterion test_ref="spt-7" negate="true" comment="Patch 111085-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2062" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0894</cveid>
			<dates>
				<created date="2005-01-04"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" />
					<criterion test_ref="wft-349" comment="the version of lsasrv.dll is less than 5.1.2600.1597" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2065" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>pam_krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0653</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
			</dates>
			<description>Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="spt-248" negate="true" comment="Patch 112908-13 or later installed" />
					<criterion test_ref="spt-236" comment="Patch 112908-12 installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-29" comment="A service is using pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" />
					<criterion test_ref="ukn-30" comment="Logging of LOG_DEBUG level messages is enabled" />
					<criterion test_ref="ukn-33" comment="System is configured to use kerberos" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2073" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0839</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html"</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2100" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1048</cveid>
			<dates>
				<created date="2004-07-30"/>
				<status_change date="2004-08-02">DRAFT</status_change>
				<status_change date="2004-08-25">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" />
					<criterion test_ref="wrt-245" negate="true" comment="the patch kb832894 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2108" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CVE">2002-1183</cveid>
			<dates>
				<created date="2004-07-12"/>
				<modified date="2004-07-13">Added superceding patch info.</modified>
				<modified date="2004-07-14">Changed to DRAFT</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862)</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2114" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0209</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-507" comment="the version of gdi32.dll is less than 5.0.2195.6945" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2137" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0215</cveid>
			<dates>
				<created date="2004-08-26"/>
				<status_change date="2004-08-26">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-170" comment="Outlook Express 5.5 SP2 is installed" />
					<criterion test_ref="wft-469" comment="the version of inetcomm.dll is less than 5.50.4942.400" />
					<criterion test_ref="wrt-494" negate="true" comment="the patch kb823353 is installed " />
				</software>
				<configuration>
					<criterion test_ref="wrt-495" comment="all users have the preview pane disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2139" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Kerberos5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0644</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
			</dates>
			<description>The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="spt-250" negate="true" comment="Patch 112908-15 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-33" comment="System is configured to use kerberos" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2155" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2004-0201</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CAN-2003-1041</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2163" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Samba</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0201</cveid>
			<dates>
				<created date="2004-12-30"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-15" comment="Samba (SUNWsmbar) installed" />
					<criterion test_ref="spt-15" negate="true" comment="Patch 114684-02 or later installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="cmp-56" comment="Inetd running and inetd.conf contains smbd" />
					<criterion test_ref="sct-3" comment="smbd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2166" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>POSIX</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0210</cveid>
			<dates>
				<created date="2004-07-13"/>
				<modified date="2004-07-14"></modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-480" negate="true" comment="the patch kb841872 is installed" />
					<criterion test_ref="cmp-1064" comment="Version check for psxss.exe on NT Workstation, Server 4.0 and NT Terminal Server" />
				</software>
				<configuration>
					<criterion test_ref="wrt-479" comment="POSIX is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2183" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-0906</cveid>
			<dates>
				<created date="2004-12-22"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-3" comment="Sendmail - root (SUNWsndmr) installed" />
					<criterion test_ref="spt-2" negate="true" comment="Patch 113575-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-208" comment="Sendmail running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2190" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>DirectX</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0202</cveid>
			<dates>
				<created date="2004-06-15"/>
				<modified date="2004-06-16">Added cmp-966 to test for vulnerable versions of DirectX</modified>
				<modified date="2004-06-17">Re-added cmp-966</modified>
				<modified date="2004-07-06">Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.</modified>
				<status_change date="2004-07-12">INTERIM</status_change>
				<status_change date="2004-07-21">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="cmp-966" comment="DirectX without KB839643 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2204" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>IIS 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2004-0205</cveid>
			<dates>
				<created date="2004-07-13"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-484" negate="true" comment="the patch q841373 is installed (Hotfix key)" />
					<criterion test_ref="wft-446" comment="the version of w3svc.dll is less than 4.2.788.1" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wmt-207" comment="Permanent redirects enabled" />
					<criterion test_ref="wrt-485" negate="true" comment="MaxClientRequestBufferData less than or equal to 16384" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2219" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0845</cveid>
			<dates>
				<created date="2004-10-26"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2245" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0420</cveid>
			<dates>
				<created date="2004-07-14"/>
				<modified date="2004-09-14"></modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-450" comment="the version of shell32.dll is less than 6.0.2800.1556" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
					<criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2265" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0112</cveid>
			<dates>
				<created date="2004-07-13"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-437" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33545" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2280" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>DHCP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0899</cveid>
			<dates>
				<created date="2004-12-16"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-156" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2300" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>SMTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0840</cveid>
			<dates>
				<created date="2004-10-19"/>
				<modified date="2004-10-26"></modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" />
					<criterion test_ref="wrt-542" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" />
					<criterion test_ref="cmp-1153" comment="Exchange Server 2003 is installed on Windows Server 2003" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2381" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0420</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-451" comment="the version of shell32.dll is less than 6.0.3790.163" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2394" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>NetDDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0206</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-518" comment="the version of nddenb32.dll is less than 4.0.1381.7268" />
					<criterion test_ref="wft-522" comment="the version of netdde.exe is less than 4.0.1381.7280" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2413" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>DirectX</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0202</cveid>
			<dates>
				<created date="2004-06-15"/>
				<modified date="2004-06-16">Changed Status to Draft; Added cmp-967</modified>
				<modified date="2004-07-06">Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.</modified>
				<modified date="2004-09-13"></modified>
				<modified date="2004-09-14"></modified>
				<modified date="2004-09-14"></modified>
				<status_change date="2004-07-12">INTERIM</status_change>
				<status_change date="2004-07-21">ACCEPTED</status_change>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-967" comment="DirectX 8.1 without kb839643 installed" />
					<criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2426" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Basic Security Module</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0654</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
			</dates>
			<description>Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic)</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="spt-233" negate="true" comment="Patch 106541-33 or later installed" />
					<criterion test_ref="spt-234" negate="true" comment="Patch 109007-18 or later installed" />
					<criterion test_ref="spt-235" negate="true" comment="Patch 114332-12 or later installed" />
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-26" comment="Basic Security Module enabled" />
					<criterion test_ref="ukn-27" comment="Auditing Administrative or System-Wide Administrative audit classes" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2428" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Enhanced Metafile (EMF)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0209</cveid>
			<dates>
				<created date="2004-10-13"/>
				<modified date="2004-10-13">changed OS</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2487" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0843</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2495" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Utility Manager</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
				<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
			</contributors>
			<cveid status="CAN">2004-0213</cveid>
			<dates>
				<created date="2004-07-13"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CAN-2003-0908</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-439" comment="the version of Sp3res.dll is less than 5.0.2195.6928" />
					<criterion test_ref="wft-442" comment="the version of Umandlg.dll is less than 1.0.0.5" />
					<criterion test_ref="wrt-481" negate="true" comment="the patch kb842526 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2505" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CAN">2004-0569</cveid>
			<dates>
				<created date="2004-10-18"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-552" comment="the version of rpcrt4.dll is less than 4.0.1381.7299" />
					<criterion test_ref="wrt-558" comment="Patch KB873350 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2516" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>DirectX</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0202</cveid>
			<dates>
				<created date="2004-06-15"/>
				<modified date="2004-06-16">Changed Status to Draft; Added cmp-969</modified>
				<modified date="2004-07-06">Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.</modified>
				<status_change date="2004-07-12">INTERIM</status_change>
				<status_change date="2004-07-21">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="cmp-969" comment="DirectX without KB839643 Installed on Windows Server 2003" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2537" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0843</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2541" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CAN">2004-1080</cveid>
			<dates>
				<created date="2005-01-03"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 4</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-163" comment="the version of wins.exe is less than 5.0.2195.7005" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2590" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Sun Cluster</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0545</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-266" negate="true" comment="Patch 113505-02 or later installed" />
					<criterion test_ref="spt-267" negate="true" comment="Patch 113508-02 or later installed" />
					<criterion test_ref="spt-268" negate="true" comment="Patch 115054-01 or later installed" />
					<criterion test_ref="spt-269" negate="true" comment="Patch 115055-01 or later installed" />
					<criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-210" comment="Apache running with SunPlex Manager config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2611" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0841</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2621" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Sun Crypto Accelerator 4000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0079</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-243" negate="true" comment="Patch 114796-04 or later installed" />
					<criterion test_ref="sat-2" comment="Sun Crypto Accelerator 4000 software installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2638" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0214</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wrt-391" comment="Windows 98 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2657" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0215</cveid>
			<dates>
				<created date="2004-08-26"/>
				<status_change date="2004-08-26">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" />
					<criterion test_ref="wrt-494" negate="true" comment="the patch kb823353 is installed " />
					<criterion test_ref="cmp-1098" comment="a vulnerable version of inetcomm.dll exisits" />
				</software>
				<configuration>
					<criterion test_ref="wrt-495" comment="all users have the preview pane disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2665" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Sun Am7990 Ethernet Driver</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0001</cveid>
			<dates>
				<created date="2004-12-30"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-16" negate="true" comment="Patch 112604-02 or later installed" />
					<criterion test_ref="spt-17" negate="true" comment="Patch 112609-02 or later installed" />
					<criterion test_ref="spt-18" negate="true" comment="Patch 115172-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sft-3" comment="Lance Ethernet (le) interface configured to start" />
					<criterion test_ref="ukn-2" comment="Lance Ethernet interface in use" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2670" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Office 2000 SP3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0573</cveid>
			<dates>
				<created date="2004-09-28"/>
				<modified date="2004-10-06"></modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " />
					<criterion test_ref="wrt-530" negate="true" comment="the patch kb873380 for Office 2000 SP3 is installed " />
					<criterion test_ref="cmp-1103" comment="Microsoft Office 2000 (Premium or Professional) Service Pack 3 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2671" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2002-0862</cveid>
			<dates>
				<created date="2004-07-11"/>
				<modified date="2004-07-12">negated patch info.</modified>
				<modified date="2004-07-13">Added superceding patch info.</modified>
				<modified date="2004-07-14">Changed to DRAFT</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" />
					<criterion test_ref="wrt-477" negate="true" comment="the patch Q329115 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2673" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Excel 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CAN">2004-0846</cveid>
			<dates>
				<created date="2004-10-18"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-535" comment="Microsoft Office 2000 Professional Service Pack 3 is installed" />
					<criterion test_ref="wrt-137" comment="Excel 2000 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2705" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>DirectX</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0202</cveid>
			<dates>
				<created date="2004-06-15"/>
				<modified date="2004-06-16">Changed Status to Draft; Added cmp-970</modified>
				<modified date="2004-07-06">Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.</modified>
				<status_change date="2004-07-12">INTERIM</status_change>
				<status_change date="2004-07-21">ACCEPTED</status_change>
			</dates>
			<description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-413" comment="Windows XP or Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="cmp-967" comment="DirectX 8.1 without kb839643 installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2706" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Office 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-24"/>
				<modified date="2004-09-27">changed affected product from GDI+ and office2003 to just office 2003</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-13">INTERIM</status_change>
				<status_change date="2004-10-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-515" comment="Microsoft Office 2003 is installed" />
					<criterion test_ref="wrt-517" negate="true" comment="Patch KB838905 is installed" />
					<criterion test_ref="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2719" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0693</cveid>
			<dates>
				<created date="2004-12-30"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CAN-2003-0695</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="spt-19" negate="true" comment="Patch 113273-04 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-4" comment="sshd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2730" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>MDAC 2.5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CVE">2002-1142</cveid>
			<dates>
				<created date="2004-08-24"/>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-482" comment="the version of msadco.dll is less than 2.53.6202.0" />
					<criterion test_ref="wrt-503" negate="true" comment="Patch Q329414 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2734" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
				<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
			</contributors>
			<cveid status="CAN">2004-1080</cveid>
			<dates>
				<created date="2004-12-17"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 4</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-165" comment="the version of wins.exe is less than 4.0.1381.33618" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2753" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-519" comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2770" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-0678</cveid>
			<dates>
				<created date="2004-10-15"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-6" comment="Toolktalk installed" />
					<criterion test_ref="spt-255" negate="true" comment="Patch 112808-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2819" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0427</cveid>
			<dates>
				<created date="2004-09-01"/>
				<status_change date="2004-09-08">DRAFT</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1100" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0" />
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2847" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>POSIX</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0210</cveid>
			<dates>
				<created date="2004-07-13"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-480" negate="true" comment="the patch kb841872 is installed" />
					<criterion test_ref="wft-441" comment="the version of psxss.exe is less than 5.0.2195.6929" />
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-479" comment="POSIX is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2894" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0420</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-413" comment="Windows XP or Windows Server 2003 is installed" />
					<criterion test_ref="wft-448" comment="the version of shell32.dll is less than 6.0.3790.168" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2906" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0842</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE&gt;@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2915" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0554</cveid>
			<dates>
				<created date="2004-09-02"/>
				<status_change date="2004-09-08">DRAFT</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Linux kernel 2.4.2x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="cmp-1100" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2961" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2004-0495</cveid>
			<dates>
				<created date="2004-09-02"/>
				<status_change date="2004-09-08">DRAFT</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="cmp-1100" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2975" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0694</cveid>
			<dates>
				<created date="2004-12-29"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-14" comment="Sendmail - user (SUNWsndmu) installed" />
					<criterion test_ref="spt-13" negate="true" comment="Patch 107684-10 or later installed" />
					<criterion test_ref="spt-14" negate="true" comment="Patch 110615-10 or later installed" />
					<criterion test_ref="spt-240" negate="true" comment="Patch 113575-05 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3038" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Project Professional 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-27"/>
				<modified date="2004-09-30">Changed affected platforms</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-523" comment="Windows Project Professional 2002 Service Pack 1 is installed" />
					<criterion test_ref="wrt-524" negate="true" comment="Patch KB831931 installed" />
					<criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3071" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1128" comment="a vulnerable version of grpconv.exe exists on NT" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3082" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Visio Professional 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-27"/>
				<modified date="2004-09-30">Changed affected platforms</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-525" comment="Visio Professional 2002 with service pack 2" />
					<criterion test_ref="wrt-526" negate="true" comment="Patch KB831932 installed" />
					<criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3095" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Explorer.exe</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2003-0306</cveid>
			<dates>
				<created date="2004-07-14"/>
				<modified date="2004-07-19"></modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-493" negate="true" comment="Patch KB821557 Installed" />
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-1074" comment="Version check for XP SP1 and XP no service pack for shell32.dll" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3120" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>NetDDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0206</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1107" comment="Windows 2000 (sp5 or earlier) is installed" />
					<criterion test_ref="wft-527" comment="the version of netdde.exe is less than 5.0.2195.6952" />
					<criterion test_ref="wft-528" comment="the version of nddenb32.dll is less than 5.0.2195.6922" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3145" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2003-0112</cveid>
			<dates>
				<created date="2004-07-13"/>
				<modified date="2004-07-14">Changed to DRAFT</modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-435" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
					<criterion test_ref="wrt-187" negate="true" comment="the patch kb835732 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3161" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>VDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0208</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-535" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3179" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2004-0201</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CAN-2003-1041</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1071" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3242" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>NetDDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0206</cveid>
			<dates>
				<created date="2004-10-15"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1152" comment="a vulnerable version of netdde.exe exists" />
					<criterion test_ref="cmp-1151" comment="a vulnerable version of nddenb32.dll exists" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3310" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0901</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3311" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0573</cveid>
			<dates>
				<created date="2004-09-23"/>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-13">INTERIM</status_change>
				<status_change date="2004-10-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-515" comment="Microsoft Office 2003 is installed" />
					<criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " />
					<criterion test_ref="wrt-516" comment="Patch KB873378 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3312" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0894</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" />
					<criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3320" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Visio Professional 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-27"/>
				<modified date="2004-09-30">Changed affected platforms</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-527" comment="Visio Professional 2003 is Installed" />
					<criterion test_ref="wrt-528" negate="true" comment="Patch KB838345 installed" />
					<criterion test_ref="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3322" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Kerberos5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0643</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
			</dates>
			<description>Double-free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="spt-250" negate="true" comment="Patch 112908-15 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="ukn-33" comment="System is configured to use kerberos" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3325" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0894</cveid>
			<dates>
				<created date="2004-12-28"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" />
					<criterion test_ref="wft-349" comment="the version of lsasrv.dll is less than 5.1.2600.1597" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3333" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office XP SP3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0573</cveid>
			<dates>
				<created date="2004-09-22"/>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" />
					<criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3372" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0842</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE&gt;@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3376" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Outlook Express</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0215</cveid>
			<dates>
				<created date="2004-08-26"/>
				<modified date="2004-09-13">cmp-66 added</modified>
				<status_change date="2004-08-26">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-171" comment="Outlook Express 6 is installed" />
					<criterion test_ref="wft-461" comment="the version of inetcomm.dll is less than 6.0.2742.200" />
					<criterion test_ref="wrt-494" negate="true" comment="the patch kb823353 is installed " />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-495" comment="all users have the preview pane disabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3386" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0420</cveid>
			<dates>
				<created date="2004-10-04"/>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-447" comment="the version of shell32.dll is less than 5.0.3900.6922" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
					<criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3391" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2003-0345</cveid>
			<dates>
				<created date="2004-07-19"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-277" negate="true" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" />
					<criterion test_ref="cmp-1094" comment="XP SP1 or pre SP1 with version check on Srv.sys" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3416" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0571</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CAN-2004-090</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-326" comment="the version of mswrd632.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3428" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Task Scheduler</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2004-0212</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-445" comment="the version of mstask.dll is less than 4.71.2195.6920" />
					<criterion test_ref="wrt-483" negate="true" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3460" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>SMTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0840</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" />
					<criterion test_ref="wrt-544" negate="true" comment="the patch WindowsServer2003-KB885881-ia64-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3483" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>NetBT Name Service</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2003-0661</cveid>
			<dates>
				<created date="2004-07-01"/>
				<modified date="2004-07-19"></modified>
				<modified date="2004-07-20"></modified>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="cmp-1051" negate="true" comment="Patch WindowsXP-KB824105-x86-ENU.exe installed on XP or XP SP1" />
					<criterion test_ref="cmp-1097" comment="XP SP1 or Pre SP1 with correct netbt.sys version" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3514" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>HTML Help Facility</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2003-1041</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CAN-2004-0475</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" />
					<criterion test_ref="wrt-482" negate="true" comment="the patch kb840315 is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-491" negate="true" comment="HTML Help is registered" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3533" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0420</cveid>
			<dates>
				<created date="2004-07-14"/>
				<status_change date="2004-08-04">INTERIM</status_change>
				<status_change date="2004-08-25">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP</description>
			<status>ACCEPTED</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
					<criterion test_ref="wft-449" comment="the version of shell32.dll is less than 6.0.2800.1517" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3573" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>MDAC 2.1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CVE">2002-1142</cveid>
			<dates>
				<created date="2004-08-24"/>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-503" negate="true" comment="Patch Q329414 Installed" />
					<criterion test_ref="wft-483" comment="the version of msadco.dll is less than 2.12.5118.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3601" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Solaris Runtime Linker</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0609</cveid>
			<dates>
				<created date="2004-12-29"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="cmp-54" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed" />
					<criterion test_ref="spt-10" negate="true" comment="Patch 106950-14 or later installed" />
					<criterion test_ref="spt-11" negate="true" comment="Patch 109147-07 or later installed" />
					<criterion test_ref="spt-12" negate="true" comment="Patch 112963-09 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3604" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0420</cveid>
			<dates>
				<created date="2004-10-04"/>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1067" comment="Windows NT 4.0 with Active Desktop Installed" />
					<criterion test_ref="wft-452" comment="the version of shell32.dll is less than 4.72.3841.1100" />
					<criterion test_ref="wrt-488" negate="true" comment="the patch kb839645 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3606" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0681</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
			</dates>
			<description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sat-3" comment="Sendmail - root (SUNWsndmr) installed" />
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-238" negate="true" comment="Patch 107684-11 or later installed" />
					<criterion test_ref="spt-239" negate="true" comment="Patch 110615-11 or later installed" />
					<criterion test_ref="spt-240" negate="true" comment="Patch 113575-05 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-208" comment="Sendmail running" />
					<criterion test_ref="ukn-36" comment="Sendmail has recipient or final rulesets" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3657" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>libpng</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2002-1363</cveid>
			<dates>
				<created date="2004-09-03"/>
				<status_change date="2004-09-08">DRAFT</status_change>
				<status_change date="2004-09-22">INTERIM</status_change>
				<status_change date="2004-10-06">ACCEPTED</status_change>
			</dates>
			<description>Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="cmp-1101" comment="libpng or libpng-devel rpm older than 1.2.2-24, Epoch 2 OR libpng10or libpng10-devel rpm older than 1.0.13-14, Epoch 0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3677" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows Internet Naming Service (WINS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CAN">2004-1080</cveid>
			<dates>
				<created date="2005-01-03"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 4</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-193" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed" />
					<criterion test_ref="wft-350" comment="the version of wins.exe is less than 5.2.3790.239" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3743" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0571</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CAN-2004-090</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
					<criterion test_ref="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3768" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wrt-550" comment="Windows ME Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3799" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0542</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-263" negate="true" comment="Patch 113146-03 or later installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3810" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Project Professional 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-24"/>
				<modified date="2004-09-30">Changed affected platforms</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-521" comment="Project Professional 2003 Installed" />
					<criterion test_ref="wrt-522" negate="true" comment="Patch KB838344 Installed" />
					<criterion test_ref="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3822" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1115" comment="a vulnerable version of shell32.dll exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3872" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0845</cveid>
			<dates>
				<created date="2004-10-26"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3881" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Office XP SP2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-10-04"/>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-514" comment="Microsoft Office XP Service Pack 2 is installed" />
					<criterion test_ref="wrt-533" negate="true" comment="Patch KB832332 installed" />
					<criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3882" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0901</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" />
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3913" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Compressed Folders</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2004-0575</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wft-537" comment="the 32-bit version of zipfldr.dll is less than 6.0.3790.198" />
					<criterion test_ref="wrt-553" negate="true" comment="the patch q873376 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-554" negate="true" comment="Compressed Folders with zipfldr.dll are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3953" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>VDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0208</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-41" comment="this is an NT Server (stand-alone)" />
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="wft-512" comment="the version of gdi32.dll is less than 4.0.1381.7270" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4003" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>GDI+</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-20"/>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-513" negate="true" comment="the patch KB833987 is installed (for Windows XP)" />
					<criterion test_ref="wft-494" comment="the version of sxs.dll is less than 5.1.2600.1363" />
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4005" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Office XP SP2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0573</cveid>
			<dates>
				<created date="2004-09-22"/>
				<status_change date="2004-09-22">DRAFT</status_change>
				<status_change date="2004-10-06">INTERIM</status_change>
				<status_change date="2004-10-20">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-514" comment="Microsoft Office XP Service Pack 2 is installed" />
					<criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4021" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0893</cveid>
			<dates>
				<created date="2004-12-16"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wft-147" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33591" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4030" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>DtMail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0800</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-264" negate="true" comment="Patch 109613-07 or later installed" />
					<criterion test_ref="spt-265" negate="true" comment="Patch 112810-06 or later installed" />
					<criterion test_ref="sat-9" comment="CDE Desktop Applications (SUNWdtdst) installed                                                                                               " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4076" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0901</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4114" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2003-0020</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-18">Change apache test to file test</modified>
				<modified date="2004-10-19">Changed apache test to package test</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="spt-254" negate="true" comment="Patch 113146-05 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4152" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0839</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html"</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4169" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0842</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE&gt;@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4216" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-10-04"/>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wrt-534" negate="true" comment="the patch q833989 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4226" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 95</windows:platform>
				<product>Microsoft Excel 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CAN">2004-0846</cveid>
			<dates>
				<created date="2004-10-18"/>
				<status_change date="2004-10-20">DRAFT</status_change>
			</dates>
			<description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-138" comment="Excel 2002 is installed" />
					<criterion test_ref="ukn-38" comment="Service Pack 2 or less for Windows Office XP" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4244" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wft-525" comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4254" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Sun Cluster</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0543</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-266" negate="true" comment="Patch 113505-02 or later installed" />
					<criterion test_ref="spt-267" negate="true" comment="Patch 113508-02 or later installed" />
					<criterion test_ref="spt-268" negate="true" comment="Patch 115054-01 or later installed" />
					<criterion test_ref="spt-269" negate="true" comment="Patch 115055-01 or later installed" />
					<criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-210" comment="Apache running with SunPlex Manager config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4264" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0892</cveid>
			<dates>
				<created date="2004-11-17"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-6" comment="the version of msphlpr.dll is less than 3.0.1200.408" />
					<criterion test_ref="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" />
					<criterion test_ref="wrt-13" comment="the patch KB888258 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4276" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Compressed Folders</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2004-0575</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wft-538" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.3790.198" />
					<criterion test_ref="wrt-553" negate="true" comment="the patch q873376 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-554" negate="true" comment="Compressed Folders with zipfldr.dll are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4307" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Visual Studio .NET 2002</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0200</cveid>
			<dates>
				<created date="2004-09-30"/>
				<status_change date="2004-10-06">DRAFT</status_change>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-531" comment="Microsoft Visual Studio .NET 2002 Installed" />
					<criterion test_ref="wrt-532" negate="true" comment="Patch KB830348 installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4316" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>VDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0208</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-505" comment="the version of vdmdbg.dll is less than 5.0.2195.6946" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4328" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0571</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CAN-2004-090</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4345" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0214</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-499" comment="the version of shell32.dll is less than 5.0.3900.6970" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4368" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Local Security Authority Subsystem Service (LSASS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0894</cveid>
			<dates>
				<created date="2004-12-28"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" />
					<criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" />
					<criterion test_ref="wft-327" comment="the version of lsasrv.dll is less than 5.1.2600.2525" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4392" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0574</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" />
					<criterion test_ref="wrt-552" negate="true" comment="the patch WindowsServer2003-KB883935-x86-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4416" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0987</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-18">Change apache test to file test</modified>
				<modified date="2004-10-19">Changed apache test to package test</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>mod_digest for Apache does not properly verify the nonce of a client response by using a AuthNonce secret</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="spt-254" negate="true" comment="Patch 113146-05 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4458" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0893</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" />
					<criterion test_ref="wrt-36" negate="true" comment="the patch kb885835is installed (Hotfix key)" />
					<criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4493" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Program Group Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0572</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="cmp-1137" comment="a vulnerable version of grpconv.exe exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4574" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Sun Cluster</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0544</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-266" negate="true" comment="Patch 113505-02 or later installed" />
					<criterion test_ref="spt-267" negate="true" comment="Patch 113508-02 or later installed" />
					<criterion test_ref="spt-268" negate="true" comment="Patch 115054-01 or later installed" />
					<criterion test_ref="spt-269" negate="true" comment="Patch 115055-01 or later installed" />
					<criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-210" comment="Apache running with SunPlex Manager config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4576" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0901</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-06">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
					<criterion test_ref="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4592" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>NetDDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0206</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wft-540" comment="the version of nddenb32.dll is less than 5.2.3790.173" />
					<criterion test_ref="wft-541" comment="the version of netdde.exe is less than 5.2.3790.184" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4661" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Kerberos5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0772</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="spt-250" negate="true" comment="Patch 112908-15 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-209" comment="Kerberos Key Distribution Center (krb5kdc) running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4670" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2003-0993</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-18">Changes apache test to file test</modified>
				<modified date="2004-10-19">Changed apache test to package test</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="spt-254" negate="true" comment="Patch 113146-05 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4702" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0727</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4741" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>HyperTerminal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2004-0568</cveid>
			<dates>
				<created date="2004-12-21"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" />
					<criterion test_ref="wft-200" comment="the version of hypertrm.dll is less than 5.0.2195.7000" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" />
					<criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4749" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Microsoft Word for Windows 6.0 Converter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CAN">2004-0901</cveid>
			<dates>
				<created date="2005-01-05"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-35" comment="Windows XP Service Pack 2" />
					<criterion test_ref="wft-300" comment="the version of mswrd6.wpc is less than 10.0.803.2" />
					<criterion test_ref="wrt-25" negate="true" comment="the patch kb885836 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4762" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>VDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0208</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-511" comment="the version of gdi32.dll is less than 4.0.1381.33566" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4767" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>IIS 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2003-0718</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-3" negate="true" comment="a Win2K/XP/2003 service pack is installed" />
					<criterion test_ref="wft-515" comment="the version of httpext.dll is less than 6.0.3790.212" />
					<criterion test_ref="wrt-549" comment="the patch KB824151 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4831" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CAN">2004-1080</cveid>
			<dates>
				<created date="2005-01-03"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 4</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" />
					<criterion test_ref="wft-164" comment="the version of wins.exe is less than 4.0.1381.7329" />
					<criterion test_ref="wrt-38" negate="true" comment="the patch KB870763 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-98" comment="the wins service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4846" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>DHCP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CAN">2004-0900</cveid>
			<dates>
				<created date="2004-12-16"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wrt-37" negate="true" comment="the patch KB885249 is installed (Hotfix key)" />
					<criterion test_ref="wft-162" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4859" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Proxy Server 2.0 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0892</cveid>
			<dates>
				<created date="2004-11-17"/>
				<status_change date="2005-01-12">DRAFT</status_change>
			</dates>
			<description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-9" comment="Microsoft Proxy Server 2.0 SP1 is installed" />
					<criterion test_ref="wft-7" comment="the version of w3proxy.dll is less than 2.0.390.16" />
					<criterion test_ref="wrt-14" comment="the patch KB888258 for Proxy Server 2.0 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4863" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0492</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-18">Changed apache test to file test</modified>
				<modified date="2004-10-19">Changed apache test to package test</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="spt-254" negate="true" comment="Patch 113146-05 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4893" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Ingrid Skoog</submitter>
			</contributors>
			<cveid status="CAN">2004-0211</cveid>
			<dates>
				<created date="2004-10-13"/>
				<modified date="2004-10-13">changed OS </modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" />
					<criterion test_ref="wrt-547" negate="true" comment="the patch KB840987 is installed (Hotfix key)" />
					<criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4936" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Kerberos5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0642</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
			</dates>
			<description>Double-free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code</description>
			<status>DRAFT</status>
			<version>0</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="spt-250" negate="true" comment="Patch 112908-15 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="ukn-33" comment="System is configured to use kerberos" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5021" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0573</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" />
					<criterion test_ref="wrt-548" negate="true" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5070" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0574</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-539" comment="the version of nntpsvc.dll is less than 5.5.1877.79" />
					<criterion test_ref="wrt-556" negate="true" comment="Patch WindowsNT4OptionPack-KB883935-x86-enu.EXE" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5074" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>NetDDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0206</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1147" comment="a vulnerable version of nddenb32.dll exists" />
					<criterion test_ref="cmp-1150" comment="a vulnerable version of netdde.exe exists" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL5277" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CAN">2003-0569</cveid>
			<dates>
				<created date="2004-10-18"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-43" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-559" comment="the version of rpcrt4.dll is less than 4.0.1381.33578" />
					<criterion test_ref="wrt-558" comment="Patch KB873350 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL5307" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
			</contributors>
			<cveid status="CAN">2004-0214</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="cmp-1118" comment="a vulnerable version of shell32.dll exists" />
					<criterion test_ref="wrt-537" negate="true" comment="the patch q841356 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL5316" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0216</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5329" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0216</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5509" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>SMTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0840</cveid>
			<dates>
				<created date="2004-10-13"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" />
					<criterion test_ref="wrt-542" negate="true" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5592" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0842</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE&gt;@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5740" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0845</cveid>
			<dates>
				<created date="2004-10-26"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL5926" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Network News Transport Protocol (NNTP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2004-0574</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" />
					<criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
					<criterion test_ref="wft-533" comment="the version of nntpsvc.dll is less than 5.0.2195.6972" />
					<criterion test_ref="wrt-555" negate="true" comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-326" comment="the NNTP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6031" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0841</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6272" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0839</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html"</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6313" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0843</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" />
					<criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" />
					<criterion test_ref="wrt-557" negate="true" comment="the patch kb834707 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6397" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Compressed Folders</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2004-0575</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-2" comment="Windows XP is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="wrt-29" negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" />
					<criterion test_ref="wft-536" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" />
					<criterion test_ref="wrt-553" negate="true" comment="the patch q873376 is installed (Hotfix key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-554" negate="true" comment="Compressed Folders with zipfldr.dll are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6579" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0842</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6.1 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE&gt;@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6600" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0216</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" />
					<criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
					<criterion test_ref="wrt-560" negate="true" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6788" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>NetDDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jonathan Baker</submitter>
			</contributors>
			<cveid status="CAN">2004-0206</cveid>
			<dates>
				<created date="2004-10-14"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" />
					<criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" />
					<criterion test_ref="cmp-1143" comment="a vulnerable version of netdde.exe exists" />
					<criterion test_ref="cmp-1144" comment="a vulnerable version of nddenb32.dll exists" />
					<criterion test_ref="wrt-551" negate="true" comment="the patch KB841533 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL6829" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0727</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7084" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0727</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7095" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0843</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL7194" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0843</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7448" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2003-0727</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " />
					<criterion test_ref="wrt-561" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7496" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0727</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-565" comment="Internet Explorer 6 Service Pack 2 for XP is installed" />
					<criterion test_ref="cmp-1154" comment="a vulnerable version of mshtml.dll exisits" />
					<criterion test_ref="wrt-564" negate="true" comment="the patch kb834707  is installed (Installed Components key) " />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7611" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0845</cveid>
			<dates>
				<created date="2004-10-26"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7717" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0216</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7721" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0839</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html"</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7865" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0216</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" />
					<criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" />
					<criterion test_ref="wrt-559" negate="true" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7906" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Internet Explorer 6</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0727</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" />
					<criterion test_ref="wrt-562" negate="true" comment="the patch kb834707 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL8127" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows ME</windows:platform>
				<product>Internet Explorer 6 SP1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
			</contributors>
			<cveid status="CAN">2004-0844</cveid>
			<dates>
				<created date="2004-10-25"/>
				<status_change date="2004-10-27">DRAFT</status_change>
				<status_change date="2004-11-17">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" />
					<criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " />
					<criterion test_ref="wft-561" negate="true" comment="the version of mshtml.dll is less than 5.0.3534.2800" />
				</software>
				<configuration>
					<criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" />
				</configuration>
			</criteria>
		</definition>
	</definitions>
	<tests>
		<compound_test id="cmp-1" comment="a vulnerable version of rpcrt4.dll exists on XP">
			<operation>OR</operation>
			<subtest test_ref="cmp-2"/>
			<subtest test_ref="cmp-6"/>
		</compound_test>
		<compound_test id="cmp-10" comment="a vulnerable version of rpcss.dll exists on XP">
			<operation>OR</operation>
			<subtest test_ref="cmp-11"/>
			<subtest test_ref="cmp-15"/>
		</compound_test>
		<compound_test id="cmp-100" comment="MDAC 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-101"/>
			<subtest test_ref="cmp-102"/>
		</compound_test>
		<compound_test id="cmp-101" comment="MDAC 2.7 (RTM) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9002.0">
			<operation>AND</operation>
			<subtest test_ref="wrt-102"/>
			<subtest test_ref="wft-37"/>
			<subtest test_ref="wft-42"/>
		</compound_test>
		<compound_test id="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition">
			<operation>AND</operation>
			<subtest test_ref="wft-414"/>
			<subtest test_ref="wrt-243"/>
		</compound_test>
		<compound_test id="cmp-1012" comment="For Terminal Server">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-415"/>
		</compound_test>
		<compound_test id="cmp-1017" comment="/usr/sbin/tcpdump is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1046"/>
			<subtest test_ref="ret-1047"/>
			<subtest test_ref="ret-1048"/>
		</compound_test>
		<compound_test id="cmp-1019" comment="/usr/bin/lha is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1049"/>
			<subtest test_ref="ret-1050"/>
			<subtest test_ref="ret-1051"/>
		</compound_test>
		<compound_test id="cmp-102" comment="MDAC 2.7 (SP1) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9042.0">
			<operation>AND</operation>
			<subtest test_ref="wrt-103"/>
			<subtest test_ref="wft-38"/>
			<subtest test_ref="wft-43"/>
		</compound_test>
		<compound_test id="cmp-1020" comment="/usr/sbin/utempter is executable">
			<operation>AND</operation>
			<subtest test_ref="ret-1052"/>
			<subtest test_ref="cmp-1021"/>
		</compound_test>
		<compound_test id="cmp-1021" comment="/usr/sbin/utempter is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1053"/>
			<subtest test_ref="ret-1054"/>
			<subtest test_ref="ret-1055"/>
		</compound_test>
		<compound_test id="cmp-1022" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-357"/>
			<subtest test_ref="rvt-358"/>
		</compound_test>
		<compound_test id="cmp-103" comment="the patch q832483 is not installed">
			<operation>OR</operation>
			<subtest test_ref="cmp-104"/>
			<subtest test_ref="cmp-105"/>
		</compound_test>
		<compound_test id="cmp-104" comment="32-bit edition of windows and patch q832483 is not installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="wrt-110"/>
		</compound_test>
		<compound_test id="cmp-1043" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition">
			<operation>AND</operation>
			<subtest test_ref="wft-416"/>
			<subtest test_ref="wrt-243"/>
		</compound_test>
		<compound_test id="cmp-1044" comment="For Terminal Server">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wrt-456"/>
		</compound_test>
		<compound_test id="cmp-1045" comment="Vulnerable versions of DirectX">
			<operation>OR</operation>
			<subtest test_ref="cmp-1046"/>
			<subtest test_ref="cmp-1047"/>
			<subtest test_ref="cmp-1048"/>
			<subtest test_ref="cmp-1049"/>
			<subtest test_ref="cmp-1050"/>
		</compound_test>
		<compound_test id="cmp-1046" comment="Unpatched DirectX 7.0">
			<operation>AND</operation>
			<subtest test_ref="wrt-461"/>
			<subtest test_ref="wft-421"/>
			<subtest test_ref="wrt-462"/>
		</compound_test>
		<compound_test id="cmp-1047" comment="Unpatched DirectX 8.0x">
			<operation>AND</operation>
			<subtest test_ref="wrt-463"/>
			<subtest test_ref="wft-422"/>
			<subtest test_ref="wrt-464"/>
		</compound_test>
		<compound_test id="cmp-1048" comment="Unpatched DirectX 8.1x">
			<operation>AND</operation>
			<subtest test_ref="wrt-465"/>
			<subtest test_ref="wft-423"/>
			<subtest test_ref="wrt-466"/>
		</compound_test>
		<compound_test id="cmp-1049" comment="Unpatched DirectX 8.2x">
			<operation>AND</operation>
			<subtest test_ref="wrt-467"/>
			<subtest test_ref="wft-424"/>
			<subtest test_ref="wrt-468"/>
		</compound_test>
		<compound_test id="cmp-105" comment="64-bit edition of windows and patch q832483 is not installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wrt-111"/>
		</compound_test>
		<compound_test id="cmp-1050" comment="Unpatched DirectX 9.0x">
			<operation>AND</operation>
			<subtest test_ref="wrt-469"/>
			<subtest test_ref="wft-425"/>
			<subtest test_ref="wrt-470"/>
		</compound_test>
		<compound_test id="cmp-1051" comment="Patch WindowsXP-KB824105-x86-ENU.exe installed on XP or XP SP1">
			<operation>OR</operation>
			<subtest test_ref="wrt-475"/>
			<subtest test_ref="wrt-476"/>
		</compound_test>
		<compound_test id="cmp-1058" comment="Windows XP 32-bit edition is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-2"/>
			<subtest test_ref="wrt-72"/>
		</compound_test>
		<compound_test id="cmp-106" comment="current user settings are being used and the downloading of signed ActiveX controls is enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-294"/>
		</compound_test>
		<compound_test id="cmp-1060" comment="This is an NT Terminal Server and the version of psxss.exe is less than 4.0.1381.33567">
			<operation>AND</operation>
			<subtest test_ref="wft-440"/>
			<subtest test_ref="wrt-43"/>
		</compound_test>
		<compound_test id="cmp-1062" comment="This is an NT Workstation or Windows NT Server 4.0 is installed">
			<operation>OR</operation>
			<subtest test_ref="cmp-44"/>
			<subtest test_ref="wrt-40"/>
		</compound_test>
		<compound_test id="cmp-1063" comment="The version of psxss.exe is less than 4.0.1381.7269 on either NT Workstation or NT Server 4.0">
			<operation>AND</operation>
			<subtest test_ref="cmp-1062"/>
			<subtest test_ref="wft-443"/>
		</compound_test>
		<compound_test id="cmp-1064" comment="Version check for psxss.exe on NT Workstation, Server 4.0 and NT Terminal Server">
			<operation>OR</operation>
			<subtest test_ref="cmp-1060"/>
			<subtest test_ref="cmp-1063"/>
		</compound_test>
		<compound_test id="cmp-1066" comment="Windows XP 64-bit with Service Pack 1">
			<operation>AND</operation>
			<subtest test_ref="wrt-2"/>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-1067" comment="Windows NT 4.0 with Active Desktop Installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-490"/>
			<subtest test_ref="wrt-77"/>
		</compound_test>
		<compound_test id="cmp-1068" comment="no service pack is installed and mstask.dll is less than 5.1.2600.155">
			<operation>AND</operation>
			<subtest test_ref="wft-453"/>
			<subtest test_ref="wrt-3"/>
		</compound_test>
		<compound_test id="cmp-1069" comment="service pack 1 is installed and mstask.dll is less than 5.1.2600.1564">
			<operation>AND</operation>
			<subtest test_ref="wft-454"/>
			<subtest test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-107" comment="local machine settings are being used and the downloading of signed ActiveX controls is enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-190"/>
		</compound_test>
		<compound_test id="cmp-1070" comment="Affected mstask.dll file versions based on service pack levels">
			<operation>OR</operation>
			<subtest test_ref="cmp-1068"/>
			<subtest test_ref="cmp-1069"/>
		</compound_test>
		<compound_test id="cmp-1071" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-50"/>
			<subtest test_ref="wrt-51"/>
			<subtest test_ref="wrt-53"/>
		</compound_test>
		<compound_test id="cmp-1072" comment="XP Service Pack 1 and version of Shell32.dll is less than 6.0.2800.1233 ">
			<operation>AND</operation>
			<subtest test_ref="wft-458"/>
			<subtest test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-1073" comment="XP no Service Pack installed and version of Shell32.dll is less than 6.0.2600.115">
			<operation>AND</operation>
			<subtest test_ref="wft-459"/>
			<subtest test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-1074" comment="Version check for XP SP1 and XP no service pack for shell32.dll">
			<operation>OR</operation>
			<subtest test_ref="cmp-1072"/>
			<subtest test_ref="cmp-1073"/>
		</compound_test>
		<compound_test id="cmp-108" comment="current user settings are being used and file downloads are enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-286"/>
		</compound_test>
		<compound_test id="cmp-1080" comment="Solaris 7,8,or 9 installed">
			<operation>OR</operation>
			<subtest test_ref="sut-202"/>
			<subtest test_ref="sut-203"/>
			<subtest test_ref="sut-204"/>
		</compound_test>
		<compound_test id="cmp-1081" comment="Solaris 8 or 9 installed">
			<operation>OR</operation>
			<subtest test_ref="sut-202"/>
			<subtest test_ref="sut-204"/>
		</compound_test>
		<compound_test id="cmp-1084" comment="Version Ntoskrnl.exe is less than 4.0.1381.7265 and this is an NT Workstation">
			<operation>AND</operation>
			<subtest test_ref="wft-343"/>
			<subtest test_ref="wrt-40"/>
		</compound_test>
		<compound_test id="cmp-1085" comment="Version check of Ntoskrnl for NT Terminal Server or NT Workstation">
			<operation>OR</operation>
			<subtest test_ref="cmp-1084"/>
			<subtest test_ref="cmp-944"/>
		</compound_test>
		<compound_test id="cmp-1086" comment="Pre Service Pack XP and netbt.sys is less than 5.1.2600.117">
			<operation>AND</operation>
			<subtest test_ref="wft-463"/>
			<subtest test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-109" comment="local machine settings are being used and file downloads are enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-191"/>
		</compound_test>
		<compound_test id="cmp-1092" comment="XP Pre- SP1 with Srv.sys is less than 5.1.2600.112">
			<operation>AND</operation>
			<subtest test_ref="wft-465"/>
			<subtest test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-1093" comment="XP SP1 and srv.sys is less than 5.1.2600.1193">
			<operation>AND</operation>
			<subtest test_ref="wft-466"/>
			<subtest test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-1094" comment="XP SP1 or pre SP1 with version check on Srv.sys">
			<operation>OR</operation>
			<subtest test_ref="cmp-1092"/>
			<subtest test_ref="cmp-1093"/>
		</compound_test>
		<compound_test id="cmp-1095" comment="Version checks on XP for Ipnathlp.dll">
			<operation>OR</operation>
			<subtest test_ref="cmp-946"/>
			<subtest test_ref="cmp-947"/>
			<subtest test_ref="cmp-948"/>
		</compound_test>
		<compound_test id="cmp-1096" comment="XP SP1 and netbt.sys is less than 5.1.2600.1243">
			<operation>AND</operation>
			<subtest test_ref="wft-464"/>
			<subtest test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-1097" comment="XP SP1 or Pre SP1 with correct netbt.sys version">
			<operation>OR</operation>
			<subtest test_ref="cmp-1086"/>
			<subtest test_ref="cmp-1096"/>
		</compound_test>
		<compound_test id="cmp-1098" comment="a vulnerable version of inetcomm.dll exisits">
			<operation>OR</operation>
			<subtest test_ref="wft-462"/>
			<subtest test_ref="wft-468"/>
		</compound_test>
		<compound_test id="cmp-11" comment="32-bit version of Windows and a vulnerable version of rpcss.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-12"/>
		</compound_test>
		<compound_test id="cmp-110" comment="current user settings are being used and cookies are enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-270"/>
			<subtest test_ref="wrt-192"/>
		</compound_test>
		<compound_test id="cmp-1100" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0">
			<operation>OR</operation>
			<subtest test_ref="rvt-364"/>
			<subtest test_ref="rvt-366"/>
			<subtest test_ref="rvt-367"/>
		</compound_test>
		<compound_test id="cmp-1101" comment="libpng or libpng-devel rpm older than 1.2.2-24, Epoch 2 OR libpng10or libpng10-devel rpm older than 1.0.13-14, Epoch 0">
			<operation>OR</operation>
			<subtest test_ref="rvt-368"/>
			<subtest test_ref="rvt-369"/>
			<subtest test_ref="rvt-370"/>
			<subtest test_ref="rvt-371"/>
		</compound_test>
		<compound_test id="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed">
			<operation>AND</operation>
			<subtest test_ref="cmp-66"/>
		</compound_test>
		<compound_test id="cmp-1103" comment="Microsoft Office 2000 (Premium or Professional) Service Pack 3 is installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-529"/>
			<subtest test_ref="wrt-535"/>
		</compound_test>
		<compound_test id="cmp-1104" comment="Patches 112237-11 and 112390-09 or greater installed">
			<operation>AND</operation>
			<subtest test_ref="spt-244"/>
			<subtest test_ref="spt-245"/>
		</compound_test>
		<compound_test id="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="wrt-538"/>
		</compound_test>
		<compound_test id="cmp-1107" comment="Windows 2000 (sp5 or earlier) is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="wrt-539"/>
		</compound_test>
		<compound_test id="cmp-1108" comment="Service pack 1 and the version of httpext.dll is less than 6.0.2600.1579">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-504"/>
		</compound_test>
		<compound_test id="cmp-1109" comment="no service pack and the version of httpext.dll is less than 6.0.2600.165">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-503"/>
		</compound_test>
		<compound_test id="cmp-111" comment="local machine settings are being used and cookies are enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-193"/>
			<subtest test_ref="wrt-194"/>
		</compound_test>
		<compound_test id="cmp-1110" comment="a vulnerable version of httpext.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-1108"/>
			<subtest test_ref="cmp-1109"/>
		</compound_test>
		<compound_test id="cmp-1112" comment="Windows XP 64-bit">
			<operation>AND</operation>
			<subtest test_ref="wrt-2"/>
			<subtest test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit">
			<operation>OR</operation>
			<subtest test_ref="cmp-1112"/>
			<subtest test_ref="wrt-61"/>
		</compound_test>
		<compound_test id="cmp-1115" comment="a vulnerable version of shell32.dll exists">
			<operation>OR</operation>
			<subtest test_ref="wft-510"/>
			<subtest test_ref="wft-509"/>
		</compound_test>
		<compound_test id="cmp-1116" comment="service pack 1 is installed and a vulnerable version of shell32.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-510"/>
		</compound_test>
		<compound_test id="cmp-1117" comment="no service pack is installed and a vulnerable version of shell32.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-514"/>
		</compound_test>
		<compound_test id="cmp-1118" comment="a vulnerable version of shell32.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-1117"/>
			<subtest test_ref="cmp-1116"/>
		</compound_test>
		<compound_test id="cmp-1119" comment="Active Desktop is not installed and shell32.dll is less than 4.0.1381.7267">
			<operation>AND</operation>
			<subtest test_ref="wrt-490"/>
			<subtest test_ref="wft-471"/>
		</compound_test>
		<compound_test id="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists">
			<operation>OR</operation>
			<subtest test_ref="wft-31"/>
			<subtest test_ref="wft-114"/>
		</compound_test>
		<compound_test id="cmp-1120" comment="Active Desktop is installed and shell32.dll is less than 4.72.3843.3100">
			<operation>AND</operation>
			<subtest test_ref="wrt-490"/>
			<subtest test_ref="wft-516"/>
		</compound_test>
		<compound_test id="cmp-1121" comment="a vulnerable version of shell32.dll exists on NT Server">
			<operation>AND</operation>
			<subtest test_ref="cmp-50"/>
			<subtest test_ref="cmp-1122"/>
		</compound_test>
		<compound_test id="cmp-1122" comment="a vulnerable version of shell32.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-1120"/>
			<subtest test_ref="cmp-1119"/>
		</compound_test>
		<compound_test id="cmp-1123" comment="a vulnerable version of shell32.dll exists on NT Terminal Server">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-517"/>
		</compound_test>
		<compound_test id="cmp-1124" comment="a vulnerable version of shell32.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-1121"/>
			<subtest test_ref="cmp-1123"/>
		</compound_test>
		<compound_test id="cmp-1126" comment="NT Server and grpconv.exe less than 4.0.1381.7286">
			<operation>AND</operation>
			<subtest test_ref="cmp-50"/>
			<subtest test_ref="wft-523"/>
		</compound_test>
		<compound_test id="cmp-1127" comment="NT Terminal Server and grpconv.exe less than 4.0.1381.33577">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-524"/>
		</compound_test>
		<compound_test id="cmp-1128" comment="a vulnerable version of grpconv.exe exists on NT">
			<operation>OR</operation>
			<subtest test_ref="cmp-1126"/>
			<subtest test_ref="cmp-1127"/>
		</compound_test>
		<compound_test id="cmp-113" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists">
			<operation>OR</operation>
			<subtest test_ref="wft-32"/>
			<subtest test_ref="wft-113"/>
		</compound_test>
		<compound_test id="cmp-1133" comment="a vulnerable version of grpconv.exe exists">
			<operation>OR</operation>
			<subtest test_ref="wft-530"/>
			<subtest test_ref="wft-531"/>
		</compound_test>
		<compound_test id="cmp-1134" comment="no service pack is installed and a vulnerable version of grpconv.exe exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-529"/>
		</compound_test>
		<compound_test id="cmp-1135" comment="service pack 1 is installed and a vulnerable version of grpconv.exe exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-530"/>
		</compound_test>
		<compound_test id="cmp-1136" comment="a vulnerable version of grpconv.exe exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-1134"/>
			<subtest test_ref="cmp-1135"/>
		</compound_test>
		<compound_test id="cmp-1137" comment="a vulnerable version of grpconv.exe exists">
			<operation>OR</operation>
			<subtest test_ref="wft-525"/>
			<subtest test_ref="wft-526"/>
		</compound_test>
		<compound_test id="cmp-1139" comment="no service pack and vulnerable 32-bit version of zipfldr.dll">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-532"/>
		</compound_test>
		<compound_test id="cmp-114" comment="a vulnerable version of helpctr.exe exists on XP">
			<operation>OR</operation>
			<subtest test_ref="cmp-126"/>
			<subtest test_ref="cmp-149"/>
		</compound_test>
		<compound_test id="cmp-1140" comment="service pack 1 and vulnerable 32-bit version of zipfldr.dll">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-534"/>
		</compound_test>
		<compound_test id="cmp-1141" comment="vulnerable 32-bit version of zipfldr.dll">
			<operation>OR</operation>
			<subtest test_ref="cmp-1139"/>
			<subtest test_ref="cmp-1140"/>
		</compound_test>
		<compound_test id="cmp-1143" comment="a vulnerable version of netdde.exe exists">
			<operation>OR</operation>
			<subtest test_ref="wft-541"/>
			<subtest test_ref="wft-543"/>
		</compound_test>
		<compound_test id="cmp-1144" comment="a vulnerable version of nddenb32.dll exists">
			<operation>OR</operation>
			<subtest test_ref="wft-540"/>
			<subtest test_ref="wft-542"/>
		</compound_test>
		<compound_test id="cmp-1145" comment="no service pack is installed and a vulnerable version of nddenb32.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-546"/>
		</compound_test>
		<compound_test id="cmp-1146" comment="Service Pack 1 is installed and a vulnerable version of nddenb32.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-545"/>
		</compound_test>
		<compound_test id="cmp-1147" comment="a vulnerable version of nddenb32.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-1145"/>
			<subtest test_ref="cmp-1146"/>
		</compound_test>
		<compound_test id="cmp-1148" comment="no service pack is installed and a vulnerable version of netdde.exe exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-547"/>
		</compound_test>
		<compound_test id="cmp-1149" comment="Service Pack 1 is installed and a vulnerable version of netdde.exe exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-544"/>
		</compound_test>
		<compound_test id="cmp-115" comment="no service pack is installed and cryptui.dll is less than 5.131.2600.117">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-249"/>
		</compound_test>
		<compound_test id="cmp-1150" comment="a vulnerable version of netdde.exe exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-1148"/>
			<subtest test_ref="cmp-1149"/>
		</compound_test>
		<compound_test id="cmp-1151" comment="a vulnerable version of nddenb32.dll exists">
			<operation>OR</operation>
			<subtest test_ref="wft-545"/>
			<subtest test_ref="wft-549"/>
		</compound_test>
		<compound_test id="cmp-1152" comment="a vulnerable version of netdde.exe exists">
			<operation>OR</operation>
			<subtest test_ref="wft-544"/>
			<subtest test_ref="wft-548"/>
		</compound_test>
		<compound_test id="cmp-1153" comment="Exchange Server 2003 is installed on Windows Server 2003">
			<operation>AND</operation>
			<subtest test_ref="wrt-61"/>
			<subtest test_ref="wrt-113"/>
		</compound_test>
		<compound_test id="cmp-1154" comment="a vulnerable version of mshtml.dll exisits">
			<operation>OR</operation>
			<subtest test_ref="wft-550"/>
			<subtest test_ref="wft-551"/>
		</compound_test>
		<compound_test id="cmp-1156" comment="The patch js56nen.exe is installed for version 5.1, 5.5, or 5.6">
			<operation>AND</operation>
			<subtest test_ref="wrt-499"/>
			<subtest test_ref="wrt-500"/>
			<subtest test_ref="wrt-501"/>
		</compound_test>
		<compound_test id="cmp-1157" comment="jscript.dll version is 5.1, 5.5, or 5.6 ">
			<operation>AND</operation>
			<subtest test_ref="wft-120"/>
			<subtest test_ref="wft-121"/>
			<subtest test_ref="wft-257"/>
		</compound_test>
		<compound_test id="cmp-117" comment="no service pack is installed and user32.dll is less than 5.1.2600.118">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-258"/>
		</compound_test>
		<compound_test id="cmp-119" comment="no service pack is installed and msgsvc.dll is less than 5.1.2600.120">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-272"/>
		</compound_test>
		<compound_test id="cmp-12" comment="a vulnerable version of rpcss.dll exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-13"/>
			<subtest test_ref="cmp-14"/>
		</compound_test>
		<compound_test id="cmp-120" comment="a vulnerable version of msgina.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-121"/>
			<subtest test_ref="cmp-125"/>
		</compound_test>
		<compound_test id="cmp-121" comment="32-bit version of Windows and a vulnerable version of msgina.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-122"/>
		</compound_test>
		<compound_test id="cmp-122" comment="a vulnerable version of msgina.dll exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-123"/>
			<subtest test_ref="cmp-124"/>
		</compound_test>
		<compound_test id="cmp-123" comment="no service pack is installed and msgina.dll is less than 5.1.2600.128">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-134"/>
		</compound_test>
		<compound_test id="cmp-124" comment="service pack 1 is installed and msgina.dll is less than 5.1.2600.1343">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-135"/>
		</compound_test>
		<compound_test id="cmp-125" comment="64-bit version of Windows and msgina.dll is less than 5.1.2600.1343">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-135"/>
		</compound_test>
		<compound_test id="cmp-126" comment="32-bit version of Windows and a vulnerable version of helpctr.exe exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-127"/>
		</compound_test>
		<compound_test id="cmp-127" comment="a vulnerable version of helpctr.exe exists exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-128"/>
			<subtest test_ref="cmp-129"/>
		</compound_test>
		<compound_test id="cmp-128" comment="service pack 1 or earlier is installed and helpctr.exe is less than 5.1.2600.137">
			<operation>AND</operation>
			<subtest test_ref="wrt-29"/>
			<subtest test_ref="wft-2"/>
		</compound_test>
		<compound_test id="cmp-129" comment="service pack 2 is installed and helpctr.exe is less than 5.1.2600.1515">
			<operation>AND</operation>
			<subtest test_ref="wrt-250"/>
			<subtest test_ref="wft-3"/>
		</compound_test>
		<compound_test id="cmp-13" comment="no service pack is installed and rpcss.dll is less than 5.1.2600.135">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-197"/>
		</compound_test>
		<compound_test id="cmp-130" comment="a vulnerable version of schannel.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-131"/>
			<subtest test_ref="cmp-135"/>
		</compound_test>
		<compound_test id="cmp-131" comment="32-bit version of Windows and a vulnerable version of schannel.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-132"/>
		</compound_test>
		<compound_test id="cmp-132" comment="a vulnerable version of schannel.dll exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-133"/>
			<subtest test_ref="cmp-134"/>
		</compound_test>
		<compound_test id="cmp-133" comment="no service pack is installed and schannel.dll is less than 5.1.2600.136">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-173"/>
		</compound_test>
		<compound_test id="cmp-134" comment="service pack 1 is installed and schannel.dll is less than 5.1.2600.1347">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-174"/>
		</compound_test>
		<compound_test id="cmp-135" comment="64-bit version of Windows and schannel.dll is less than 5.1.2600.1347">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-174"/>
		</compound_test>
		<compound_test id="cmp-136" comment="a vulnerable version of msgina.dll exists on NT">
			<operation>OR</operation>
			<subtest test_ref="cmp-137"/>
			<subtest test_ref="cmp-138"/>
		</compound_test>
		<compound_test id="cmp-137" comment="non Terminal Server and msgina.dll is less than 4.0.1381.7255">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-131"/>
		</compound_test>
		<compound_test id="cmp-138" comment="Terminal Server and msgina.dll is less than 4.0.1381.33559">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-132"/>
		</compound_test>
		<compound_test id="cmp-139" comment="Windows NT or 2000 is installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-77"/>
			<subtest test_ref="wrt-1"/>
		</compound_test>
		<compound_test id="cmp-14" comment="service pack 1 is installed and rpcss.dll is less than 5.1.2600.1361">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-198"/>
		</compound_test>
		<compound_test id="cmp-140" comment="a vulnerable version of Microsoft Jet 4.0 is installed">
			<operation>OR</operation>
			<subtest test_ref="cmp-141"/>
			<subtest test_ref="cmp-142"/>
		</compound_test>
		<compound_test id="cmp-141" comment="32-bit version of Windows and msjet40.dll is less than 4.0.8618.0">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="wft-180"/>
		</compound_test>
		<compound_test id="cmp-142" comment="64-bit version of Windows and wmsjet40.dll is less than 4.0.8618.0">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-181"/>
		</compound_test>
		<compound_test id="cmp-143" comment="a vulnerable version of lsasrv.dll exists on XP">
			<operation>OR</operation>
			<subtest test_ref="cmp-144"/>
			<subtest test_ref="cmp-148"/>
		</compound_test>
		<compound_test id="cmp-144" comment="32-bit version of Windows and a vulnerable version of lsasrv.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-145"/>
		</compound_test>
		<compound_test id="cmp-145" comment="a vulnerable version of lsasrv.dll exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-146"/>
			<subtest test_ref="cmp-147"/>
		</compound_test>
		<compound_test id="cmp-146" comment="no service pack is installed and lsasrv.dll is less than 5.1.2600.134">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-158"/>
		</compound_test>
		<compound_test id="cmp-147" comment="service pack 1 is installed and lsasrv.dll is less than 5.1.2600.1361">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-159"/>
		</compound_test>
		<compound_test id="cmp-148" comment="64-bit version of Windows and lsasrv.dll is less than 5.1.2600.1361">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-159"/>
		</compound_test>
		<compound_test id="cmp-149" comment="64-bit version of Windows and helpctr.exe is less than 5.1.2600.1515">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-3"/>
		</compound_test>
		<compound_test id="cmp-15" comment="64-bit version of Windows and rpcss.dll is less than 5.1.2600.1361">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-198"/>
		</compound_test>
		<compound_test id="cmp-150" comment="a vulnerable version of msasn1.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-151"/>
			<subtest test_ref="cmp-155"/>
		</compound_test>
		<compound_test id="cmp-151" comment="32-bit version of Windows and a vulnerable version of msasn1.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-152"/>
		</compound_test>
		<compound_test id="cmp-152" comment="a vulnerable version of msasn1.dll exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-153"/>
			<subtest test_ref="cmp-154"/>
		</compound_test>
		<compound_test id="cmp-153" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.137">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-195"/>
		</compound_test>
		<compound_test id="cmp-154" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1362">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-196"/>
		</compound_test>
		<compound_test id="cmp-155" comment="64-bit version of Windows and msasn1.dll is less than 5.1.2600.1362">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-196"/>
		</compound_test>
		<compound_test id="cmp-16" comment="a vulnerable version of rpcss.dll exists on Server 2003">
			<operation>OR</operation>
			<subtest test_ref="cmp-18"/>
			<subtest test_ref="cmp-20"/>
		</compound_test>
		<compound_test id="cmp-160" comment="a vulnerable version of h323.tsp exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-161"/>
			<subtest test_ref="cmp-165"/>
		</compound_test>
		<compound_test id="cmp-161" comment="32-bit version of Windows and a vulnerable version of h323.tsp exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-162"/>
		</compound_test>
		<compound_test id="cmp-162" comment="a vulnerable version of h323.tsp exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-163"/>
			<subtest test_ref="cmp-164"/>
		</compound_test>
		<compound_test id="cmp-163" comment="no service pack is installed and h323.tsp is less than 5.1.2600.134">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-153"/>
		</compound_test>
		<compound_test id="cmp-164" comment="service pack 1 is installed and h323.tsp is less than 5.1.2600.1348">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-152"/>
		</compound_test>
		<compound_test id="cmp-165" comment="64-bit version of Windows and h323.tsp is less than 5.1.2600.1348">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-152"/>
		</compound_test>
		<compound_test id="cmp-17" comment="a vulnerable version of rpcrt4.dll exists on Server 2003">
			<operation>OR</operation>
			<subtest test_ref="ukn-16"/>
			<subtest test_ref="ukn-17"/>
		</compound_test>
		<compound_test id="cmp-170" comment="a vulnerable version of mf3216.dll exists on XP">
			<operation>OR</operation>
			<subtest test_ref="cmp-171"/>
			<subtest test_ref="cmp-175"/>
		</compound_test>
		<compound_test id="cmp-171" comment="32-bit version of Windows and a vulnerable version of mf3216.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-172"/>
		</compound_test>
		<compound_test id="cmp-172" comment="a vulnerable version of mf3216.dll exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-173"/>
			<subtest test_ref="cmp-174"/>
		</compound_test>
		<compound_test id="cmp-173" comment="no service pack is installed and mf3216.dll is less than 5.1.2600.132">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-139"/>
		</compound_test>
		<compound_test id="cmp-174" comment="service pack 1 is installed and mf3216.dll is less than 5.1.2600.1331">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-149"/>
		</compound_test>
		<compound_test id="cmp-175" comment="64-bit version of Windows and mf3216.dll is less than 5.1.2600.1331">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-149"/>
		</compound_test>
		<compound_test id="cmp-18" comment="32-bit machine a vulnerable version of rpcss.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-19"/>
		</compound_test>
		<compound_test id="cmp-19" comment="a vulnerable version of rpcss.dll exists on non 64-bit Server 2003">
			<operation>OR</operation>
			<subtest test_ref="ukn-18"/>
			<subtest test_ref="ukn-19"/>
		</compound_test>
		<compound_test id="cmp-190" comment="a vulnerable version of rpcproxy.dll exists on Server 2003">
			<operation>OR</operation>
			<subtest test_ref="wft-284"/>
			<subtest test_ref="wft-288"/>
		</compound_test>
		<compound_test id="cmp-193" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-61"/>
			<subtest test_ref="wrt-40"/>
		</compound_test>
		<compound_test id="cmp-195" comment="a vulnerable version of ole32.dll exists on NT">
			<operation>OR</operation>
			<subtest test_ref="cmp-196"/>
			<subtest test_ref="cmp-197"/>
		</compound_test>
		<compound_test id="cmp-196" comment="non Terminal Server and ole32.dll is less than 4.0.1381.7263">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-295"/>
		</compound_test>
		<compound_test id="cmp-197" comment="Terminal Server and ole32.dll is less than 4.0.1381.33562">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-297"/>
		</compound_test>
		<compound_test id="cmp-198" comment="non Terminal Server and rpcproxy.dll is less than 4.0.1381.7255">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-298"/>
		</compound_test>
		<compound_test id="cmp-199" comment="Terminal Server and rpcproxy.dll is less than 4.0.1381.33559">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-299"/>
		</compound_test>
		<compound_test id="cmp-2" comment="32-bit version of Windows and a vulnerable version of rpcrt4.dll exists">
			<operation>AND</operation>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="cmp-3"/>
		</compound_test>
		<compound_test id="cmp-20" comment="64-bit machine and rpcss.dll is less than 5.2.3790.146">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-199"/>
		</compound_test>
		<compound_test id="cmp-201" comment="/usr/bin/balsa is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-201"/>
			<subtest test_ref="ret-202"/>
			<subtest test_ref="ret-203"/>
		</compound_test>
		<compound_test id="cmp-202" comment="File kcms_configure executable and SUID or SGID">
			<operation>AND</operation>
			<subtest test_ref="set-204"/>
			<subtest test_ref="cmp-203"/>
		</compound_test>
		<compound_test id="cmp-203" comment="File kcms_configure executable and SUID or SGID">
			<operation>OR</operation>
			<subtest test_ref="set-205"/>
			<subtest test_ref="set-206"/>
		</compound_test>
		<compound_test id="cmp-204" comment="rpc.cmsd or dmispd exist">
			<operation>OR</operation>
			<subtest test_ref="sft-202"/>
			<subtest test_ref="sft-203"/>
		</compound_test>
		<compound_test id="cmp-205" comment="Patches 108827-30 and 108901-06">
			<operation>AND</operation>
			<subtest test_ref="spt-201"/>
			<subtest test_ref="spt-202"/>
		</compound_test>
		<compound_test id="cmp-206" comment="rpc.cmsd enabled OR dmispd running">
			<operation>OR</operation>
			<subtest test_ref="cmp-207"/>
			<subtest test_ref="sct-202"/>
		</compound_test>
		<compound_test id="cmp-207" comment="rpc.cmsd enabled">
			<operation>AND</operation>
			<subtest test_ref="sit-201"/>
			<subtest test_ref="sct-201"/>
			<subtest test_ref="cmp-208"/>
		</compound_test>
		<compound_test id="cmp-208" comment="File rpc.cmsd executable">
			<operation>OR</operation>
			<subtest test_ref="set-207"/>
			<subtest test_ref="set-208"/>
			<subtest test_ref="set-209"/>
		</compound_test>
		<compound_test id="cmp-209" comment="File xlock SUID and executable">
			<operation>AND</operation>
			<subtest test_ref="set-210"/>
			<subtest test_ref="set-211"/>
		</compound_test>
		<compound_test id="cmp-21" comment="a vulnerable version of rpcproxy.dll exists on NT">
			<operation>OR</operation>
			<subtest test_ref="cmp-198"/>
			<subtest test_ref="cmp-199"/>
		</compound_test>
		<compound_test id="cmp-210" comment="File Xsun SGID and executable">
			<operation>AND</operation>
			<subtest test_ref="set-212"/>
			<subtest test_ref="set-213"/>
		</compound_test>
		<compound_test id="cmp-211" comment="File rpc.ttdbserverd executable">
			<operation>OR</operation>
			<subtest test_ref="set-214"/>
			<subtest test_ref="set-215"/>
			<subtest test_ref="set-216"/>
		</compound_test>
		<compound_test id="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="wrt-28"/>
		</compound_test>
		<compound_test id="cmp-213" comment="Internet Explorer 5.5 Installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-225"/>
			<subtest test_ref="wrt-226"/>
			<subtest test_ref="wrt-227"/>
		</compound_test>
		<compound_test id="cmp-214" comment="Internet Explorer 5.01 Installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-230"/>
			<subtest test_ref="wrt-231"/>
			<subtest test_ref="wrt-232"/>
			<subtest test_ref="wrt-233"/>
			<subtest test_ref="wrt-234"/>
			<subtest test_ref="wrt-235"/>
			<subtest test_ref="wrt-236"/>
			<subtest test_ref="wrt-56"/>
		</compound_test>
		<compound_test id="cmp-215" comment="Windows 2000 Service Pack 4 (or later) is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="wrt-222"/>
		</compound_test>
		<compound_test id="cmp-216" comment="Vulnerable config">
			<operation>OR</operation>
			<subtest test_ref="rvt-203"/>
			<subtest test_ref="rvt-204"/>
		</compound_test>
		<compound_test id="cmp-217" comment="File cachefsd executable">
			<operation>OR</operation>
			<subtest test_ref="set-217"/>
			<subtest test_ref="set-218"/>
			<subtest test_ref="set-219"/>
		</compound_test>
		<compound_test id="cmp-219" comment="File whodo SUID and executable">
			<operation>AND</operation>
			<subtest test_ref="set-220"/>
			<subtest test_ref="set-221"/>
		</compound_test>
		<compound_test id="cmp-220" comment="Windows 2000 (domain controller) is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="wrt-42"/>
		</compound_test>
		<compound_test id="cmp-221" comment="File rpc.rwalld executable">
			<operation>OR</operation>
			<subtest test_ref="set-222"/>
			<subtest test_ref="set-223"/>
			<subtest test_ref="set-224"/>
		</compound_test>
		<compound_test id="cmp-223" comment="Patches 106942-22 and 108451-06">
			<operation>AND</operation>
			<subtest test_ref="spt-211"/>
			<subtest test_ref="spt-212"/>
		</compound_test>
		<compound_test id="cmp-229" comment="File admintool SUID and executable">
			<operation>AND</operation>
			<subtest test_ref="set-225"/>
			<subtest test_ref="set-226"/>
		</compound_test>
		<compound_test id="cmp-230" comment="Internet Explorer 5.01 Installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-230"/>
			<subtest test_ref="wrt-231"/>
			<subtest test_ref="wrt-232"/>
			<subtest test_ref="wrt-233"/>
			<subtest test_ref="wrt-234"/>
			<subtest test_ref="wrt-235"/>
			<subtest test_ref="wrt-236"/>
			<subtest test_ref="wrt-56"/>
			<subtest test_ref="wrt-55"/>
		</compound_test>
		<compound_test id="cmp-232" comment="eog is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-227"/>
			<subtest test_ref="ret-228"/>
			<subtest test_ref="ret-229"/>
		</compound_test>
		<compound_test id="cmp-238" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-207"/>
			<subtest test_ref="rvt-208"/>
		</compound_test>
		<compound_test id="cmp-239" comment="File dtspcd executable">
			<operation>OR</operation>
			<subtest test_ref="set-230"/>
			<subtest test_ref="set-231"/>
			<subtest test_ref="set-232"/>
		</compound_test>
		<compound_test id="cmp-247" comment="File lbxproxy SGID and executable">
			<operation>AND</operation>
			<subtest test_ref="set-233"/>
			<subtest test_ref="set-234"/>
		</compound_test>
		<compound_test id="cmp-25" comment="patch kb889293 is installed (hotfix or ID)">
			<operation>OR</operation>
			<subtest test_ref="wrt-23"/>
			<subtest test_ref="wrt-24"/>
		</compound_test>
		<compound_test id="cmp-250" comment="cookies are enabled">
			<operation>AND</operation>
			<subtest test_ref="cmp-110"/>
			<subtest test_ref="cmp-111"/>
		</compound_test>
		<compound_test id="cmp-255" comment="File kcms_server executable and SUID or SGID">
			<operation>OR</operation>
			<subtest test_ref="set-235"/>
			<subtest test_ref="set-236"/>
			<subtest test_ref="set-237"/>
		</compound_test>
		<compound_test id="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-18"/>
			<subtest test_ref="wrt-50"/>
		</compound_test>
		<compound_test id="cmp-262" comment="/usr/bin/gs is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-238"/>
			<subtest test_ref="ret-239"/>
			<subtest test_ref="ret-240"/>
		</compound_test>
		<compound_test id="cmp-263" comment="/usr/bin/gnupg is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-241"/>
			<subtest test_ref="ret-242"/>
		</compound_test>
		<compound_test id="cmp-264" comment="Internet Explorer 5.01 Installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-230"/>
			<subtest test_ref="wrt-231"/>
			<subtest test_ref="wrt-232"/>
			<subtest test_ref="wrt-233"/>
			<subtest test_ref="wrt-234"/>
			<subtest test_ref="wrt-235"/>
		</compound_test>
		<compound_test id="cmp-265" comment="file downloads are enabled">
			<operation>AND</operation>
			<subtest test_ref="cmp-108"/>
			<subtest test_ref="cmp-109"/>
		</compound_test>
		<compound_test id="cmp-266" comment="/usr/bin/evolution is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-243"/>
			<subtest test_ref="ret-244"/>
			<subtest test_ref="ret-245"/>
		</compound_test>
		<compound_test id="cmp-267" comment="File xfs executable">
			<operation>OR</operation>
			<subtest test_ref="set-246"/>
			<subtest test_ref="set-247"/>
			<subtest test_ref="set-248"/>
		</compound_test>
		<compound_test id="cmp-271" comment="Internet Explorer 5.5 Installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-225"/>
			<subtest test_ref="wrt-226"/>
			<subtest test_ref="wrt-227"/>
			<subtest test_ref="wrt-53"/>
		</compound_test>
		<compound_test id="cmp-273" comment="a vulnerable version of cryptui.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-115"/>
			<subtest test_ref="cmp-274"/>
		</compound_test>
		<compound_test id="cmp-274" comment="service pack 1 is installed and cryptui.dll is less than 5.131.2600.1243">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-250"/>
		</compound_test>
		<compound_test id="cmp-275" comment="downloading of signed ActiveX controls is enabled">
			<operation>AND</operation>
			<subtest test_ref="cmp-106"/>
			<subtest test_ref="cmp-107"/>
		</compound_test>
		<compound_test id="cmp-276" comment="ActiveX Enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-298"/>
		</compound_test>
		<compound_test id="cmp-278" comment="/usr/bin/kdm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-249"/>
			<subtest test_ref="ret-250"/>
			<subtest test_ref="ret-251"/>
		</compound_test>
		<compound_test id="cmp-282" comment="a vulnerable version of user32.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-117"/>
			<subtest test_ref="cmp-283"/>
		</compound_test>
		<compound_test id="cmp-283" comment="service pack 1 is installed and user32.dll is less than 5.1.2600.1255">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-259"/>
		</compound_test>
		<compound_test id="cmp-289" comment="krb5-server or krb5-workstation installed">
			<operation>OR</operation>
			<subtest test_ref="rvt-218"/>
			<subtest test_ref="rvt-220"/>
		</compound_test>
		<compound_test id="cmp-295" comment="a vulnerable version of msgsvc.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-119"/>
			<subtest test_ref="cmp-296"/>
		</compound_test>
		<compound_test id="cmp-296" comment="service pack 1 is installed and msgsvc.dll is less than 5.1.2600.1301">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-273"/>
		</compound_test>
		<compound_test id="cmp-3" comment="a vulnerable version of rpcrt4.dll exists depending on service pack level">
			<operation>OR</operation>
			<subtest test_ref="cmp-4"/>
			<subtest test_ref="cmp-5"/>
		</compound_test>
		<compound_test id="cmp-30" comment="a vulnerable version of wkssvc.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-31"/>
			<subtest test_ref="cmp-32"/>
		</compound_test>
		<compound_test id="cmp-304" comment="/usr/bin/konqueror is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-252"/>
			<subtest test_ref="ret-253"/>
			<subtest test_ref="ret-254"/>
		</compound_test>
		<compound_test id="cmp-305" comment="/usr/bin/mutt is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-256"/>
			<subtest test_ref="ret-257"/>
			<subtest test_ref="ret-258"/>
		</compound_test>
		<compound_test id="cmp-31" comment="no service pack is installed and wkssvc.dll is less than 5.1.2600.120">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-20"/>
		</compound_test>
		<compound_test id="cmp-314" comment="/usr/bin/pine is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-259"/>
			<subtest test_ref="ret-260"/>
			<subtest test_ref="ret-261"/>
		</compound_test>
		<compound_test id="cmp-319" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-244"/>
			<subtest test_ref="rvt-245"/>
		</compound_test>
		<compound_test id="cmp-32" comment="service pack 1 is installed and wkssvc.dll is less than 5.1.2600.1301">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-21"/>
		</compound_test>
		<compound_test id="cmp-320" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="cmp-321"/>
			<subtest test_ref="cmp-322"/>
		</compound_test>
		<compound_test id="cmp-321" comment="/usr/bin/emacs is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-262"/>
			<subtest test_ref="ret-263"/>
			<subtest test_ref="ret-264"/>
		</compound_test>
		<compound_test id="cmp-322" comment="/usr/bin/xemacs is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-265"/>
			<subtest test_ref="ret-266"/>
			<subtest test_ref="ret-267"/>
		</compound_test>
		<compound_test id="cmp-323" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="cmp-324"/>
			<subtest test_ref="cmp-326"/>
			<subtest test_ref="rlt-211"/>
		</compound_test>
		<compound_test id="cmp-324" comment="sendmail is Set-UID">
			<operation>AND</operation>
			<subtest test_ref="ret-268"/>
			<subtest test_ref="cmp-325"/>
		</compound_test>
		<compound_test id="cmp-325" comment="sendmail is Set-UID">
			<operation>OR</operation>
			<subtest test_ref="ret-269"/>
			<subtest test_ref="ret-270"/>
		</compound_test>
		<compound_test id="cmp-326" comment="sendmail is Set-GID">
			<operation>AND</operation>
			<subtest test_ref="ret-271"/>
			<subtest test_ref="ret-270"/>
		</compound_test>
		<compound_test id="cmp-33" comment="The version of mswrd664.wpc OR wmswrd632.wpc is less than 2004.10.25.0">
			<operation>OR</operation>
			<subtest test_ref="wft-264"/>
			<subtest test_ref="wft-265"/>
		</compound_test>
		<compound_test id="cmp-335" comment="/usr/bin/unzip is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-272"/>
			<subtest test_ref="ret-273"/>
			<subtest test_ref="ret-274"/>
		</compound_test>
		<compound_test id="cmp-338" comment="xpdf is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-275"/>
			<subtest test_ref="ret-276"/>
			<subtest test_ref="ret-277"/>
		</compound_test>
		<compound_test id="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition ">
			<operation>AND</operation>
			<subtest test_ref="wrt-61"/>
			<subtest test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-341" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-258"/>
			<subtest test_ref="rvt-259"/>
			<subtest test_ref="rvt-260"/>
		</compound_test>
		<compound_test id="cmp-342" comment="Vulnerable configuration">
			<operation>OR</operation>
			<subtest test_ref="cmp-343"/>
			<subtest test_ref="cmp-344"/>
			<subtest test_ref="cmp-345"/>
			<subtest test_ref="cmp-346"/>
			<subtest test_ref="cmp-347"/>
			<subtest test_ref="cmp-348"/>
			<subtest test_ref="cmp-349"/>
			<subtest test_ref="cmp-350"/>
			<subtest test_ref="cmp-351"/>
			<subtest test_ref="cmp-352"/>
			<subtest test_ref="cmp-353"/>
			<subtest test_ref="cmp-354"/>
			<subtest test_ref="cmp-355"/>
			<subtest test_ref="cmp-356"/>
			<subtest test_ref="cmp-357"/>
			<subtest test_ref="cmp-358"/>
			<subtest test_ref="cmp-359"/>
			<subtest test_ref="cmp-360"/>
			<subtest test_ref="cmp-361"/>
			<subtest test_ref="cmp-362"/>
			<subtest test_ref="cmp-363"/>
			<subtest test_ref="cmp-364"/>
			<subtest test_ref="cmp-365"/>
			<subtest test_ref="cmp-366"/>
			<subtest test_ref="cmp-367"/>
			<subtest test_ref="cmp-368"/>
			<subtest test_ref="cmp-369"/>
			<subtest test_ref="cmp-370"/>
			<subtest test_ref="cmp-371"/>
			<subtest test_ref="cmp-372"/>
			<subtest test_ref="cmp-373"/>
			<subtest test_ref="cmp-374"/>
			<subtest test_ref="cmp-375"/>
			<subtest test_ref="cmp-376"/>
			<subtest test_ref="cmp-377"/>
			<subtest test_ref="cmp-378"/>
			<subtest test_ref="cmp-379"/>
			<subtest test_ref="cmp-380"/>
			<subtest test_ref="cmp-381"/>
			<subtest test_ref="cmp-382"/>
			<subtest test_ref="cmp-383"/>
			<subtest test_ref="cmp-384"/>
			<subtest test_ref="cmp-385"/>
			<subtest test_ref="cmp-386"/>
			<subtest test_ref="cmp-387"/>
			<subtest test_ref="cmp-388"/>
			<subtest test_ref="cmp-389"/>
			<subtest test_ref="cmp-390"/>
			<subtest test_ref="cmp-391"/>
			<subtest test_ref="cmp-392"/>
			<subtest test_ref="cmp-393"/>
			<subtest test_ref="cmp-394"/>
			<subtest test_ref="cmp-395"/>
			<subtest test_ref="cmp-396"/>
			<subtest test_ref="cmp-397"/>
			<subtest test_ref="cmp-398"/>
			<subtest test_ref="cmp-399"/>
			<subtest test_ref="cmp-400"/>
			<subtest test_ref="cmp-401"/>
			<subtest test_ref="cmp-402"/>
			<subtest test_ref="cmp-403"/>
			<subtest test_ref="cmp-404"/>
			<subtest test_ref="cmp-405"/>
			<subtest test_ref="cmp-406"/>
			<subtest test_ref="cmp-407"/>
			<subtest test_ref="cmp-408"/>
			<subtest test_ref="cmp-409"/>
			<subtest test_ref="cmp-410"/>
			<subtest test_ref="cmp-411"/>
			<subtest test_ref="cmp-412"/>
			<subtest test_ref="cmp-413"/>
			<subtest test_ref="cmp-414"/>
			<subtest test_ref="cmp-415"/>
			<subtest test_ref="cmp-416"/>
			<subtest test_ref="cmp-417"/>
			<subtest test_ref="cmp-418"/>
			<subtest test_ref="cmp-419"/>
			<subtest test_ref="cmp-420"/>
			<subtest test_ref="cmp-421"/>
			<subtest test_ref="cmp-422"/>
			<subtest test_ref="cmp-423"/>
			<subtest test_ref="cmp-424"/>
			<subtest test_ref="cmp-425"/>
			<subtest test_ref="cmp-426"/>
			<subtest test_ref="cmp-427"/>
			<subtest test_ref="cmp-428"/>
			<subtest test_ref="cmp-429"/>
			<subtest test_ref="cmp-430"/>
			<subtest test_ref="cmp-431"/>
			<subtest test_ref="cmp-432"/>
			<subtest test_ref="cmp-433"/>
			<subtest test_ref="cmp-434"/>
			<subtest test_ref="cmp-435"/>
			<subtest test_ref="cmp-436"/>
			<subtest test_ref="cmp-437"/>
			<subtest test_ref="cmp-438"/>
			<subtest test_ref="cmp-439"/>
			<subtest test_ref="cmp-440"/>
			<subtest test_ref="cmp-441"/>
			<subtest test_ref="cmp-442"/>
			<subtest test_ref="cmp-443"/>
			<subtest test_ref="cmp-444"/>
			<subtest test_ref="cmp-445"/>
			<subtest test_ref="cmp-446"/>
			<subtest test_ref="cmp-447"/>
			<subtest test_ref="cmp-448"/>
			<subtest test_ref="cmp-449"/>
			<subtest test_ref="cmp-450"/>
			<subtest test_ref="cmp-451"/>
			<subtest test_ref="cmp-452"/>
			<subtest test_ref="cmp-453"/>
			<subtest test_ref="cmp-454"/>
			<subtest test_ref="cmp-455"/>
			<subtest test_ref="cmp-456"/>
			<subtest test_ref="cmp-457"/>
			<subtest test_ref="cmp-458"/>
			<subtest test_ref="cmp-459"/>
			<subtest test_ref="cmp-460"/>
			<subtest test_ref="cmp-461"/>
			<subtest test_ref="cmp-462"/>
			<subtest test_ref="cmp-463"/>
			<subtest test_ref="cmp-464"/>
			<subtest test_ref="cmp-465"/>
			<subtest test_ref="cmp-466"/>
			<subtest test_ref="cmp-467"/>
			<subtest test_ref="cmp-526"/>
			<subtest test_ref="cmp-527"/>
			<subtest test_ref="cmp-528"/>
			<subtest test_ref="cmp-529"/>
			<subtest test_ref="cmp-530"/>
			<subtest test_ref="cmp-531"/>
			<subtest test_ref="cmp-532"/>
			<subtest test_ref="cmp-533"/>
			<subtest test_ref="cmp-534"/>
			<subtest test_ref="cmp-535"/>
			<subtest test_ref="cmp-536"/>
			<subtest test_ref="cmp-537"/>
			<subtest test_ref="cmp-538"/>
			<subtest test_ref="cmp-539"/>
			<subtest test_ref="cmp-540"/>
			<subtest test_ref="cmp-541"/>
			<subtest test_ref="cmp-542"/>
			<subtest test_ref="cmp-543"/>
			<subtest test_ref="cmp-544"/>
			<subtest test_ref="cmp-545"/>
			<subtest test_ref="cmp-546"/>
			<subtest test_ref="cmp-547"/>
			<subtest test_ref="cmp-548"/>
			<subtest test_ref="cmp-549"/>
			<subtest test_ref="cmp-550"/>
			<subtest test_ref="cmp-551"/>
			<subtest test_ref="cmp-552"/>
			<subtest test_ref="cmp-553"/>
			<subtest test_ref="cmp-554"/>
			<subtest test_ref="cmp-555"/>
			<subtest test_ref="cmp-556"/>
			<subtest test_ref="cmp-557"/>
			<subtest test_ref="cmp-558"/>
			<subtest test_ref="cmp-559"/>
			<subtest test_ref="cmp-560"/>
			<subtest test_ref="cmp-561"/>
			<subtest test_ref="cmp-562"/>
			<subtest test_ref="cmp-563"/>
			<subtest test_ref="cmp-564"/>
			<subtest test_ref="cmp-565"/>
			<subtest test_ref="cmp-566"/>
			<subtest test_ref="cmp-567"/>
			<subtest test_ref="cmp-468"/>
			<subtest test_ref="cmp-469"/>
			<subtest test_ref="cmp-470"/>
			<subtest test_ref="cmp-471"/>
			<subtest test_ref="cmp-472"/>
			<subtest test_ref="cmp-473"/>
			<subtest test_ref="cmp-474"/>
			<subtest test_ref="cmp-475"/>
			<subtest test_ref="cmp-476"/>
			<subtest test_ref="cmp-477"/>
			<subtest test_ref="cmp-478"/>
			<subtest test_ref="cmp-479"/>
			<subtest test_ref="cmp-480"/>
			<subtest test_ref="cmp-481"/>
			<subtest test_ref="cmp-482"/>
			<subtest test_ref="cmp-483"/>
			<subtest test_ref="cmp-484"/>
			<subtest test_ref="cmp-485"/>
			<subtest test_ref="cmp-486"/>
			<subtest test_ref="cmp-487"/>
			<subtest test_ref="cmp-488"/>
			<subtest test_ref="cmp-489"/>
			<subtest test_ref="cmp-490"/>
			<subtest test_ref="cmp-491"/>
			<subtest test_ref="cmp-492"/>
			<subtest test_ref="cmp-493"/>
			<subtest test_ref="cmp-494"/>
			<subtest test_ref="cmp-495"/>
			<subtest test_ref="cmp-496"/>
			<subtest test_ref="cmp-497"/>
			<subtest test_ref="cmp-498"/>
			<subtest test_ref="cmp-499"/>
			<subtest test_ref="cmp-500"/>
			<subtest test_ref="cmp-501"/>
			<subtest test_ref="cmp-502"/>
			<subtest test_ref="cmp-503"/>
			<subtest test_ref="cmp-504"/>
			<subtest test_ref="cmp-505"/>
			<subtest test_ref="cmp-506"/>
			<subtest test_ref="cmp-507"/>
			<subtest test_ref="cmp-508"/>
			<subtest test_ref="cmp-509"/>
			<subtest test_ref="cmp-510"/>
			<subtest test_ref="cmp-511"/>
			<subtest test_ref="cmp-512"/>
			<subtest test_ref="cmp-513"/>
			<subtest test_ref="cmp-514"/>
			<subtest test_ref="cmp-515"/>
			<subtest test_ref="cmp-516"/>
			<subtest test_ref="cmp-517"/>
			<subtest test_ref="cmp-518"/>
			<subtest test_ref="cmp-519"/>
			<subtest test_ref="cmp-520"/>
			<subtest test_ref="cmp-521"/>
			<subtest test_ref="cmp-522"/>
			<subtest test_ref="cmp-523"/>
			<subtest test_ref="cmp-524"/>
			<subtest test_ref="cmp-525"/>
		</compound_test>
		<compound_test id="cmp-343" comment="/usr/bin/411toppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-279"/>
			<subtest test_ref="ret-280"/>
			<subtest test_ref="ret-281"/>
		</compound_test>
		<compound_test id="cmp-344" comment="/usr/bin/asciitopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-282"/>
			<subtest test_ref="ret-283"/>
			<subtest test_ref="ret-284"/>
		</compound_test>
		<compound_test id="cmp-345" comment="/usr/bin/atktopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-285"/>
			<subtest test_ref="ret-286"/>
			<subtest test_ref="ret-287"/>
		</compound_test>
		<compound_test id="cmp-346" comment="/usr/bin/bioradtopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-288"/>
			<subtest test_ref="ret-289"/>
			<subtest test_ref="ret-290"/>
		</compound_test>
		<compound_test id="cmp-347" comment="/usr/bin/bmptoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-291"/>
			<subtest test_ref="ret-292"/>
			<subtest test_ref="ret-293"/>
		</compound_test>
		<compound_test id="cmp-348" comment="/usr/bin/brushtopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-294"/>
			<subtest test_ref="ret-295"/>
			<subtest test_ref="ret-296"/>
		</compound_test>
		<compound_test id="cmp-349" comment="/usr/bin/cmuwmtopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-297"/>
			<subtest test_ref="ret-298"/>
			<subtest test_ref="ret-299"/>
		</compound_test>
		<compound_test id="cmp-35" comment="Windows XP Service Pack 2">
			<operation>AND</operation>
			<subtest test_ref="wrt-250"/>
			<subtest test_ref="cmp-1058"/>
		</compound_test>
		<compound_test id="cmp-350" comment="/usr/bin/eyuvtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-300"/>
			<subtest test_ref="ret-301"/>
			<subtest test_ref="ret-302"/>
		</compound_test>
		<compound_test id="cmp-351" comment="/usr/bin/fiascotopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-303"/>
			<subtest test_ref="ret-304"/>
			<subtest test_ref="ret-305"/>
		</compound_test>
		<compound_test id="cmp-352" comment="/usr/bin/fitstopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-306"/>
			<subtest test_ref="ret-307"/>
			<subtest test_ref="ret-308"/>
		</compound_test>
		<compound_test id="cmp-353" comment="/usr/bin/fstopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-309"/>
			<subtest test_ref="ret-310"/>
			<subtest test_ref="ret-311"/>
		</compound_test>
		<compound_test id="cmp-354" comment="/usr/bin/g3topbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-312"/>
			<subtest test_ref="ret-313"/>
			<subtest test_ref="ret-314"/>
		</compound_test>
		<compound_test id="cmp-355" comment="/usr/bin/gemtopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-315"/>
			<subtest test_ref="ret-316"/>
			<subtest test_ref="ret-317"/>
		</compound_test>
		<compound_test id="cmp-356" comment="/usr/bin/gemtopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-318"/>
			<subtest test_ref="ret-319"/>
			<subtest test_ref="ret-320"/>
		</compound_test>
		<compound_test id="cmp-357" comment="/usr/bin/giftopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-321"/>
			<subtest test_ref="ret-322"/>
			<subtest test_ref="ret-323"/>
		</compound_test>
		<compound_test id="cmp-358" comment="/usr/bin/gouldtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-324"/>
			<subtest test_ref="ret-325"/>
			<subtest test_ref="ret-326"/>
		</compound_test>
		<compound_test id="cmp-359" comment="/usr/bin/hipstopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-327"/>
			<subtest test_ref="ret-328"/>
			<subtest test_ref="ret-329"/>
		</compound_test>
		<compound_test id="cmp-360" comment="/usr/bin/hpcdtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-330"/>
			<subtest test_ref="ret-331"/>
			<subtest test_ref="ret-332"/>
		</compound_test>
		<compound_test id="cmp-361" comment="/usr/bin/icontopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-333"/>
			<subtest test_ref="ret-334"/>
			<subtest test_ref="ret-335"/>
		</compound_test>
		<compound_test id="cmp-362" comment="/usr/bin/ilbmtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-336"/>
			<subtest test_ref="ret-337"/>
			<subtest test_ref="ret-338"/>
		</compound_test>
		<compound_test id="cmp-363" comment="/usr/bin/imgtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-339"/>
			<subtest test_ref="ret-340"/>
			<subtest test_ref="ret-341"/>
		</compound_test>
		<compound_test id="cmp-364" comment="/usr/bin/jpegtopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-342"/>
			<subtest test_ref="ret-343"/>
			<subtest test_ref="ret-344"/>
		</compound_test>
		<compound_test id="cmp-365" comment="/usr/bin/leaftoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-345"/>
			<subtest test_ref="ret-346"/>
			<subtest test_ref="ret-347"/>
		</compound_test>
		<compound_test id="cmp-366" comment="/usr/bin/lispmtopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-348"/>
			<subtest test_ref="ret-349"/>
			<subtest test_ref="ret-350"/>
		</compound_test>
		<compound_test id="cmp-367" comment="/usr/bin/macptopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-351"/>
			<subtest test_ref="ret-352"/>
			<subtest test_ref="ret-353"/>
		</compound_test>
		<compound_test id="cmp-368" comment="/usr/bin/mdatopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-354"/>
			<subtest test_ref="ret-355"/>
			<subtest test_ref="ret-356"/>
		</compound_test>
		<compound_test id="cmp-369" comment="/usr/bin/mgrtopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-357"/>
			<subtest test_ref="ret-358"/>
			<subtest test_ref="ret-359"/>
		</compound_test>
		<compound_test id="cmp-370" comment="/usr/bin/mtvtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-360"/>
			<subtest test_ref="ret-361"/>
			<subtest test_ref="ret-362"/>
		</compound_test>
		<compound_test id="cmp-371" comment="/usr/bin/neotoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-363"/>
			<subtest test_ref="ret-364"/>
			<subtest test_ref="ret-365"/>
		</compound_test>
		<compound_test id="cmp-372" comment="/usr/bin/palmtopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-366"/>
			<subtest test_ref="ret-367"/>
			<subtest test_ref="ret-368"/>
		</compound_test>
		<compound_test id="cmp-373" comment="/usr/bin/pamchannel is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-369"/>
			<subtest test_ref="ret-370"/>
			<subtest test_ref="ret-371"/>
		</compound_test>
		<compound_test id="cmp-374" comment="/usr/bin/pamcut is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-372"/>
			<subtest test_ref="ret-373"/>
			<subtest test_ref="ret-374"/>
		</compound_test>
		<compound_test id="cmp-375" comment="/usr/bin/pamdeinterlace is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-375"/>
			<subtest test_ref="ret-376"/>
			<subtest test_ref="ret-377"/>
		</compound_test>
		<compound_test id="cmp-376" comment="/usr/bin/pamfile is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-378"/>
			<subtest test_ref="ret-379"/>
			<subtest test_ref="ret-380"/>
		</compound_test>
		<compound_test id="cmp-377" comment="/usr/bin/pamoil is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-381"/>
			<subtest test_ref="ret-382"/>
			<subtest test_ref="ret-383"/>
		</compound_test>
		<compound_test id="cmp-378" comment="/usr/bin/pamstretch is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-384"/>
			<subtest test_ref="ret-385"/>
			<subtest test_ref="ret-386"/>
		</compound_test>
		<compound_test id="cmp-379" comment="/usr/bin/pamtopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-387"/>
			<subtest test_ref="ret-388"/>
			<subtest test_ref="ret-389"/>
		</compound_test>
		<compound_test id="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
			<operation>OR</operation>
			<subtest test_ref="wrt-61"/>
			<subtest test_ref="cmp-1112"/>
		</compound_test>
		<compound_test id="cmp-380" comment="/usr/bin/pbmclean is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-390"/>
			<subtest test_ref="ret-391"/>
			<subtest test_ref="ret-392"/>
		</compound_test>
		<compound_test id="cmp-381" comment="/usr/bin/pbmlife is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-393"/>
			<subtest test_ref="ret-394"/>
			<subtest test_ref="ret-395"/>
		</compound_test>
		<compound_test id="cmp-382" comment="/usr/bin/pbmmake is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-396"/>
			<subtest test_ref="ret-397"/>
			<subtest test_ref="ret-398"/>
		</compound_test>
		<compound_test id="cmp-383" comment="/usr/bin/pbmmask is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-399"/>
			<subtest test_ref="ret-400"/>
			<subtest test_ref="ret-401"/>
		</compound_test>
		<compound_test id="cmp-384" comment="/usr/bin/pbmpage is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-402"/>
			<subtest test_ref="ret-403"/>
			<subtest test_ref="ret-404"/>
		</compound_test>
		<compound_test id="cmp-385" comment="/usr/bin/pbmpscale is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-405"/>
			<subtest test_ref="ret-406"/>
			<subtest test_ref="ret-407"/>
		</compound_test>
		<compound_test id="cmp-386" comment="/usr/bin/pbmreduce is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-408"/>
			<subtest test_ref="ret-409"/>
			<subtest test_ref="ret-410"/>
		</compound_test>
		<compound_test id="cmp-387" comment="/usr/bin/pbmtext is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-411"/>
			<subtest test_ref="ret-412"/>
			<subtest test_ref="ret-413"/>
		</compound_test>
		<compound_test id="cmp-388" comment="/usr/bin/pbmto10x is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-414"/>
			<subtest test_ref="ret-415"/>
			<subtest test_ref="ret-416"/>
		</compound_test>
		<compound_test id="cmp-389" comment="/usr/bin/pbmto4425 is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-417"/>
			<subtest test_ref="ret-418"/>
			<subtest test_ref="ret-419"/>
		</compound_test>
		<compound_test id="cmp-390" comment="/usr/bin/pbmtoascii is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-420"/>
			<subtest test_ref="ret-421"/>
			<subtest test_ref="ret-422"/>
		</compound_test>
		<compound_test id="cmp-391" comment="/usr/bin/pbmtoatk is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-423"/>
			<subtest test_ref="ret-424"/>
			<subtest test_ref="ret-425"/>
		</compound_test>
		<compound_test id="cmp-392" comment="/usr/bin/pbmtobbnbg is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-426"/>
			<subtest test_ref="ret-427"/>
			<subtest test_ref="ret-428"/>
		</compound_test>
		<compound_test id="cmp-393" comment="/usr/bin/pbmtocmuwm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-429"/>
			<subtest test_ref="ret-430"/>
			<subtest test_ref="ret-431"/>
		</compound_test>
		<compound_test id="cmp-394" comment="/usr/bin/pbmtoepsi is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-432"/>
			<subtest test_ref="ret-433"/>
			<subtest test_ref="ret-434"/>
		</compound_test>
		<compound_test id="cmp-395" comment="/usr/bin/pbmtoepson is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-435"/>
			<subtest test_ref="ret-436"/>
			<subtest test_ref="ret-437"/>
		</compound_test>
		<compound_test id="cmp-396" comment="/usr/bin/pbmtog3 is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-438"/>
			<subtest test_ref="ret-439"/>
			<subtest test_ref="ret-440"/>
		</compound_test>
		<compound_test id="cmp-397" comment="/usr/bin/pbmtogem is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-441"/>
			<subtest test_ref="ret-442"/>
			<subtest test_ref="ret-443"/>
		</compound_test>
		<compound_test id="cmp-398" comment="/usr/bin/pbmtogo is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-444"/>
			<subtest test_ref="ret-445"/>
			<subtest test_ref="ret-446"/>
		</compound_test>
		<compound_test id="cmp-399" comment="/usr/bin/pbmtoicon is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-447"/>
			<subtest test_ref="ret-448"/>
			<subtest test_ref="ret-449"/>
		</compound_test>
		<compound_test id="cmp-4" comment="no service pack is installed and rpcrt4.dll is less than 5.1.2600.135">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-187"/>
		</compound_test>
		<compound_test id="cmp-400" comment="/usr/bin/pbmtolj is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-450"/>
			<subtest test_ref="ret-451"/>
			<subtest test_ref="ret-452"/>
		</compound_test>
		<compound_test id="cmp-401" comment="/usr/bin/pbmtoln03 is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-453"/>
			<subtest test_ref="ret-454"/>
			<subtest test_ref="ret-455"/>
		</compound_test>
		<compound_test id="cmp-402" comment="/usr/bin/pbmtolps is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-456"/>
			<subtest test_ref="ret-457"/>
			<subtest test_ref="ret-458"/>
		</compound_test>
		<compound_test id="cmp-403" comment="/usr/bin/pbmtomacp is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-459"/>
			<subtest test_ref="ret-460"/>
			<subtest test_ref="ret-461"/>
		</compound_test>
		<compound_test id="cmp-404" comment="/usr/bin/pbmtomda is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-462"/>
			<subtest test_ref="ret-463"/>
			<subtest test_ref="ret-464"/>
		</compound_test>
		<compound_test id="cmp-405" comment="/usr/bin/pbmtomgr is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-465"/>
			<subtest test_ref="ret-466"/>
			<subtest test_ref="ret-467"/>
		</compound_test>
		<compound_test id="cmp-406" comment="/usr/bin/pbmtonokia is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-468"/>
			<subtest test_ref="ret-469"/>
			<subtest test_ref="ret-470"/>
		</compound_test>
		<compound_test id="cmp-407" comment="/usr/bin/pbmtopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-471"/>
			<subtest test_ref="ret-472"/>
			<subtest test_ref="ret-473"/>
		</compound_test>
		<compound_test id="cmp-408" comment="/usr/bin/pbmtopi3 is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-474"/>
			<subtest test_ref="ret-475"/>
			<subtest test_ref="ret-476"/>
		</compound_test>
		<compound_test id="cmp-409" comment="/usr/bin/pbmtopk is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-477"/>
			<subtest test_ref="ret-478"/>
			<subtest test_ref="ret-479"/>
		</compound_test>
		<compound_test id="cmp-410" comment="/usr/bin/pbmtoplot is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-480"/>
			<subtest test_ref="ret-481"/>
			<subtest test_ref="ret-482"/>
		</compound_test>
		<compound_test id="cmp-411" comment="/usr/bin/pbmtoppa is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-483"/>
			<subtest test_ref="ret-484"/>
			<subtest test_ref="ret-485"/>
		</compound_test>
		<compound_test id="cmp-412" comment="/usr/bin/pbmtopsg3 is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-486"/>
			<subtest test_ref="ret-487"/>
			<subtest test_ref="ret-488"/>
		</compound_test>
		<compound_test id="cmp-413" comment="/usr/bin/pbmtoptx is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-489"/>
			<subtest test_ref="ret-490"/>
			<subtest test_ref="ret-491"/>
		</compound_test>
		<compound_test id="cmp-414" comment="/usr/bin/pbmtowbmp is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-492"/>
			<subtest test_ref="ret-493"/>
			<subtest test_ref="ret-494"/>
		</compound_test>
		<compound_test id="cmp-415" comment="/usr/bin/pbmtox10bm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-495"/>
			<subtest test_ref="ret-496"/>
			<subtest test_ref="ret-497"/>
		</compound_test>
		<compound_test id="cmp-416" comment="/usr/bin/pbmtoxbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-498"/>
			<subtest test_ref="ret-499"/>
			<subtest test_ref="ret-500"/>
		</compound_test>
		<compound_test id="cmp-417" comment="/usr/bin/pbmtoybm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-501"/>
			<subtest test_ref="ret-502"/>
			<subtest test_ref="ret-503"/>
		</compound_test>
		<compound_test id="cmp-418" comment="/usr/bin/pbmtozinc is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-504"/>
			<subtest test_ref="ret-505"/>
			<subtest test_ref="ret-506"/>
		</compound_test>
		<compound_test id="cmp-419" comment="/usr/bin/pbmupc is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-507"/>
			<subtest test_ref="ret-508"/>
			<subtest test_ref="ret-509"/>
		</compound_test>
		<compound_test id="cmp-420" comment="/usr/bin/pcxtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-510"/>
			<subtest test_ref="ret-511"/>
			<subtest test_ref="ret-512"/>
		</compound_test>
		<compound_test id="cmp-421" comment="/usr/bin/pgmbentley is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-513"/>
			<subtest test_ref="ret-514"/>
			<subtest test_ref="ret-515"/>
		</compound_test>
		<compound_test id="cmp-422" comment="/usr/bin/pgmcrater is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-516"/>
			<subtest test_ref="ret-517"/>
			<subtest test_ref="ret-518"/>
		</compound_test>
		<compound_test id="cmp-423" comment="/usr/bin/pgmedge is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-519"/>
			<subtest test_ref="ret-520"/>
			<subtest test_ref="ret-521"/>
		</compound_test>
		<compound_test id="cmp-424" comment="/usr/bin/pgmenhance is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-522"/>
			<subtest test_ref="ret-523"/>
			<subtest test_ref="ret-524"/>
		</compound_test>
		<compound_test id="cmp-425" comment="/usr/bin/pgmhist is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-525"/>
			<subtest test_ref="ret-526"/>
			<subtest test_ref="ret-527"/>
		</compound_test>
		<compound_test id="cmp-426" comment="/usr/bin/pgmkernel is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-528"/>
			<subtest test_ref="ret-529"/>
			<subtest test_ref="ret-530"/>
		</compound_test>
		<compound_test id="cmp-427" comment="/usr/bin/pgmnoise is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-531"/>
			<subtest test_ref="ret-532"/>
			<subtest test_ref="ret-533"/>
		</compound_test>
		<compound_test id="cmp-428" comment="/usr/bin/pgmnorm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-534"/>
			<subtest test_ref="ret-535"/>
			<subtest test_ref="ret-536"/>
		</compound_test>
		<compound_test id="cmp-429" comment="/usr/bin/pgmoil is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-537"/>
			<subtest test_ref="ret-538"/>
			<subtest test_ref="ret-539"/>
		</compound_test>
		<compound_test id="cmp-43" comment="Solaris 7 or 8 installed">
			<operation>OR</operation>
			<subtest test_ref="sut-203"/>
			<subtest test_ref="sut-202"/>
		</compound_test>
		<compound_test id="cmp-430" comment="/usr/bin/pgmramp is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-540"/>
			<subtest test_ref="ret-541"/>
			<subtest test_ref="ret-542"/>
		</compound_test>
		<compound_test id="cmp-431" comment="/usr/bin/pgmslice is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-543"/>
			<subtest test_ref="ret-544"/>
			<subtest test_ref="ret-545"/>
		</compound_test>
		<compound_test id="cmp-432" comment="/usr/bin/pgmtexture is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-546"/>
			<subtest test_ref="ret-547"/>
			<subtest test_ref="ret-548"/>
		</compound_test>
		<compound_test id="cmp-433" comment="/usr/bin/pgmtofs is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-549"/>
			<subtest test_ref="ret-550"/>
			<subtest test_ref="ret-551"/>
		</compound_test>
		<compound_test id="cmp-434" comment="/usr/bin/pgmtolispm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-552"/>
			<subtest test_ref="ret-553"/>
			<subtest test_ref="ret-554"/>
		</compound_test>
		<compound_test id="cmp-435" comment="/usr/bin/pgmtopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-555"/>
			<subtest test_ref="ret-556"/>
			<subtest test_ref="ret-557"/>
		</compound_test>
		<compound_test id="cmp-436" comment="/usr/bin/pgmtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-558"/>
			<subtest test_ref="ret-559"/>
			<subtest test_ref="ret-560"/>
		</compound_test>
		<compound_test id="cmp-437" comment="/usr/bin/pi1toppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-561"/>
			<subtest test_ref="ret-562"/>
			<subtest test_ref="ret-563"/>
		</compound_test>
		<compound_test id="cmp-438" comment="/usr/bin/pi3topbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-564"/>
			<subtest test_ref="ret-565"/>
			<subtest test_ref="ret-566"/>
		</compound_test>
		<compound_test id="cmp-439" comment="/usr/bin/pjtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-567"/>
			<subtest test_ref="ret-568"/>
			<subtest test_ref="ret-569"/>
		</compound_test>
		<compound_test id="cmp-44" comment="Windows NT Server 4.0 is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-77"/>
			<subtest test_ref="cmp-50"/>
		</compound_test>
		<compound_test id="cmp-440" comment="/usr/bin/pktopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-570"/>
			<subtest test_ref="ret-571"/>
			<subtest test_ref="ret-572"/>
		</compound_test>
		<compound_test id="cmp-441" comment="/usr/bin/pngtopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-573"/>
			<subtest test_ref="ret-574"/>
			<subtest test_ref="ret-575"/>
		</compound_test>
		<compound_test id="cmp-442" comment="/usr/bin/pnmalias is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-576"/>
			<subtest test_ref="ret-577"/>
			<subtest test_ref="ret-578"/>
		</compound_test>
		<compound_test id="cmp-443" comment="/usr/bin/pnmarith is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-579"/>
			<subtest test_ref="ret-580"/>
			<subtest test_ref="ret-581"/>
		</compound_test>
		<compound_test id="cmp-444" comment="/usr/bin/pnmcat is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-582"/>
			<subtest test_ref="ret-583"/>
			<subtest test_ref="ret-584"/>
		</compound_test>
		<compound_test id="cmp-445" comment="/usr/bin/pnmcolormap is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-585"/>
			<subtest test_ref="ret-586"/>
			<subtest test_ref="ret-587"/>
		</compound_test>
		<compound_test id="cmp-446" comment="/usr/bin/pnmcomp is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-588"/>
			<subtest test_ref="ret-589"/>
			<subtest test_ref="ret-590"/>
		</compound_test>
		<compound_test id="cmp-447" comment="/usr/bin/pnmconvol is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-591"/>
			<subtest test_ref="ret-592"/>
			<subtest test_ref="ret-593"/>
		</compound_test>
		<compound_test id="cmp-448" comment="/usr/bin/pnmcrop is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-594"/>
			<subtest test_ref="ret-595"/>
			<subtest test_ref="ret-596"/>
		</compound_test>
		<compound_test id="cmp-449" comment="/usr/bin/pnmcut is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-597"/>
			<subtest test_ref="ret-598"/>
			<subtest test_ref="ret-599"/>
		</compound_test>
		<compound_test id="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-77"/>
			<subtest test_ref="wrt-43"/>
		</compound_test>
		<compound_test id="cmp-450" comment="/usr/bin/pnmdepth is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-600"/>
			<subtest test_ref="ret-601"/>
			<subtest test_ref="ret-602"/>
		</compound_test>
		<compound_test id="cmp-451" comment="/usr/bin/pnmenlarge is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-603"/>
			<subtest test_ref="ret-604"/>
			<subtest test_ref="ret-605"/>
		</compound_test>
		<compound_test id="cmp-452" comment="/usr/bin/pnmfile is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-606"/>
			<subtest test_ref="ret-607"/>
			<subtest test_ref="ret-608"/>
		</compound_test>
		<compound_test id="cmp-453" comment="/usr/bin/pnmflip is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-609"/>
			<subtest test_ref="ret-610"/>
			<subtest test_ref="ret-611"/>
		</compound_test>
		<compound_test id="cmp-454" comment="/usr/bin/pnmgamma is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-612"/>
			<subtest test_ref="ret-613"/>
			<subtest test_ref="ret-614"/>
		</compound_test>
		<compound_test id="cmp-455" comment="/usr/bin/pnmhisteq is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-615"/>
			<subtest test_ref="ret-616"/>
			<subtest test_ref="ret-617"/>
		</compound_test>
		<compound_test id="cmp-456" comment="/usr/bin/pnmhistmap is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-618"/>
			<subtest test_ref="ret-619"/>
			<subtest test_ref="ret-620"/>
		</compound_test>
		<compound_test id="cmp-457" comment="/usr/bin/pnminterp is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-621"/>
			<subtest test_ref="ret-622"/>
			<subtest test_ref="ret-623"/>
		</compound_test>
		<compound_test id="cmp-458" comment="/usr/bin/pnminvert is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-624"/>
			<subtest test_ref="ret-625"/>
			<subtest test_ref="ret-626"/>
		</compound_test>
		<compound_test id="cmp-459" comment="/usr/bin/pnmmontage is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-627"/>
			<subtest test_ref="ret-628"/>
			<subtest test_ref="ret-629"/>
		</compound_test>
		<compound_test id="cmp-460" comment="/usr/bin/pnmnlfilt is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-630"/>
			<subtest test_ref="ret-631"/>
			<subtest test_ref="ret-632"/>
		</compound_test>
		<compound_test id="cmp-461" comment="/usr/bin/pnmnoraw is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-633"/>
			<subtest test_ref="ret-634"/>
			<subtest test_ref="ret-635"/>
		</compound_test>
		<compound_test id="cmp-462" comment="/usr/bin/pnmpad is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-636"/>
			<subtest test_ref="ret-637"/>
			<subtest test_ref="ret-638"/>
		</compound_test>
		<compound_test id="cmp-463" comment="/usr/bin/pnmpaste is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-639"/>
			<subtest test_ref="ret-640"/>
			<subtest test_ref="ret-641"/>
		</compound_test>
		<compound_test id="cmp-464" comment="/usr/bin/pnmpsnr is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-642"/>
			<subtest test_ref="ret-643"/>
			<subtest test_ref="ret-644"/>
		</compound_test>
		<compound_test id="cmp-465" comment="/usr/bin/pnmremap is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-645"/>
			<subtest test_ref="ret-646"/>
			<subtest test_ref="ret-647"/>
		</compound_test>
		<compound_test id="cmp-466" comment="/usr/bin/pnmrotate is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-648"/>
			<subtest test_ref="ret-649"/>
			<subtest test_ref="ret-650"/>
		</compound_test>
		<compound_test id="cmp-467" comment="/usr/bin/pnmscale is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-651"/>
			<subtest test_ref="ret-652"/>
			<subtest test_ref="ret-653"/>
		</compound_test>
		<compound_test id="cmp-468" comment="/usr/bin/pnmscalefixed is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-654"/>
			<subtest test_ref="ret-655"/>
			<subtest test_ref="ret-656"/>
		</compound_test>
		<compound_test id="cmp-469" comment="/usr/bin/pnmshear is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-657"/>
			<subtest test_ref="ret-658"/>
			<subtest test_ref="ret-659"/>
		</compound_test>
		<compound_test id="cmp-470" comment="/usr/bin/pnmsmooth is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-660"/>
			<subtest test_ref="ret-661"/>
			<subtest test_ref="ret-662"/>
		</compound_test>
		<compound_test id="cmp-471" comment="/usr/bin/pnmsplit is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-663"/>
			<subtest test_ref="ret-664"/>
			<subtest test_ref="ret-665"/>
		</compound_test>
		<compound_test id="cmp-472" comment="/usr/bin/pnmtile is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-666"/>
			<subtest test_ref="ret-667"/>
			<subtest test_ref="ret-668"/>
		</compound_test>
		<compound_test id="cmp-473" comment="/usr/bin/pnmtoddif is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-669"/>
			<subtest test_ref="ret-670"/>
			<subtest test_ref="ret-671"/>
		</compound_test>
		<compound_test id="cmp-474" comment="/usr/bin/pnmtofiasco is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-672"/>
			<subtest test_ref="ret-673"/>
			<subtest test_ref="ret-674"/>
		</compound_test>
		<compound_test id="cmp-475" comment="/usr/bin/pnmtofits is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-675"/>
			<subtest test_ref="ret-676"/>
			<subtest test_ref="ret-677"/>
		</compound_test>
		<compound_test id="cmp-476" comment="/usr/bin/pnmtojpeg is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-678"/>
			<subtest test_ref="ret-679"/>
			<subtest test_ref="ret-680"/>
		</compound_test>
		<compound_test id="cmp-477" comment="/usr/bin/pnmtopalm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-681"/>
			<subtest test_ref="ret-682"/>
			<subtest test_ref="ret-683"/>
		</compound_test>
		<compound_test id="cmp-478" comment="/usr/bin/pnmtoplainpnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-684"/>
			<subtest test_ref="ret-685"/>
			<subtest test_ref="ret-686"/>
		</compound_test>
		<compound_test id="cmp-479" comment="/usr/bin/pnmtopng is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-687"/>
			<subtest test_ref="ret-688"/>
			<subtest test_ref="ret-689"/>
		</compound_test>
		<compound_test id="cmp-480" comment="/usr/bin/pnmtops is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-690"/>
			<subtest test_ref="ret-691"/>
			<subtest test_ref="ret-692"/>
		</compound_test>
		<compound_test id="cmp-481" comment="/usr/bin/pnmtorast is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-693"/>
			<subtest test_ref="ret-694"/>
			<subtest test_ref="ret-695"/>
		</compound_test>
		<compound_test id="cmp-482" comment="/usr/bin/pnmtorle is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-696"/>
			<subtest test_ref="ret-697"/>
			<subtest test_ref="ret-698"/>
		</compound_test>
		<compound_test id="cmp-483" comment="/usr/bin/pnmtosgi is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-699"/>
			<subtest test_ref="ret-700"/>
			<subtest test_ref="ret-701"/>
		</compound_test>
		<compound_test id="cmp-484" comment="/usr/bin/pnmtosir is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-702"/>
			<subtest test_ref="ret-703"/>
			<subtest test_ref="ret-704"/>
		</compound_test>
		<compound_test id="cmp-485" comment="/usr/bin/pnmtotiff is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-705"/>
			<subtest test_ref="ret-706"/>
			<subtest test_ref="ret-707"/>
		</compound_test>
		<compound_test id="cmp-486" comment="/usr/bin/pnmtotiffcmyk is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-708"/>
			<subtest test_ref="ret-709"/>
			<subtest test_ref="ret-710"/>
		</compound_test>
		<compound_test id="cmp-487" comment="/usr/bin/pnmtoxwd is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-711"/>
			<subtest test_ref="ret-712"/>
			<subtest test_ref="ret-713"/>
		</compound_test>
		<compound_test id="cmp-488" comment="/usr/bin/ppm3d is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-714"/>
			<subtest test_ref="ret-715"/>
			<subtest test_ref="ret-716"/>
		</compound_test>
		<compound_test id="cmp-489" comment="/usr/bin/ppmbrighten is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-717"/>
			<subtest test_ref="ret-718"/>
			<subtest test_ref="ret-719"/>
		</compound_test>
		<compound_test id="cmp-490" comment="/usr/bin/ppmchange is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-720"/>
			<subtest test_ref="ret-721"/>
			<subtest test_ref="ret-722"/>
		</compound_test>
		<compound_test id="cmp-491" comment="/usr/bin/ppmcie is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-723"/>
			<subtest test_ref="ret-724"/>
			<subtest test_ref="ret-725"/>
		</compound_test>
		<compound_test id="cmp-492" comment="/usr/bin/ppmcolormask is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-726"/>
			<subtest test_ref="ret-727"/>
			<subtest test_ref="ret-728"/>
		</compound_test>
		<compound_test id="cmp-493" comment="/usr/bin/ppmcolors is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-729"/>
			<subtest test_ref="ret-730"/>
			<subtest test_ref="ret-731"/>
		</compound_test>
		<compound_test id="cmp-494" comment="/usr/bin/ppmdim is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-732"/>
			<subtest test_ref="ret-733"/>
			<subtest test_ref="ret-734"/>
		</compound_test>
		<compound_test id="cmp-495" comment="/usr/bin/ppmdist is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-735"/>
			<subtest test_ref="ret-736"/>
			<subtest test_ref="ret-737"/>
		</compound_test>
		<compound_test id="cmp-496" comment="/usr/bin/ppmdither is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-738"/>
			<subtest test_ref="ret-739"/>
			<subtest test_ref="ret-740"/>
		</compound_test>
		<compound_test id="cmp-497" comment="/usr/bin/ppmflash is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-741"/>
			<subtest test_ref="ret-742"/>
			<subtest test_ref="ret-743"/>
		</compound_test>
		<compound_test id="cmp-498" comment="/usr/bin/ppmforge is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-744"/>
			<subtest test_ref="ret-745"/>
			<subtest test_ref="ret-746"/>
		</compound_test>
		<compound_test id="cmp-499" comment="/usr/bin/ppmhist is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-747"/>
			<subtest test_ref="ret-748"/>
			<subtest test_ref="ret-749"/>
		</compound_test>
		<compound_test id="cmp-5" comment="service pack 1 is installed and rpcrt4.dll is less than 5.1.2600.1361">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-188"/>
		</compound_test>
		<compound_test id="cmp-50" comment="Windows NT server product option">
			<operation>OR</operation>
			<subtest test_ref="wrt-41"/>
			<subtest test_ref="wrt-42"/>
		</compound_test>
		<compound_test id="cmp-500" comment="/usr/bin/ppmlabel is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-750"/>
			<subtest test_ref="ret-751"/>
			<subtest test_ref="ret-752"/>
		</compound_test>
		<compound_test id="cmp-501" comment="/usr/bin/ppmmake is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-753"/>
			<subtest test_ref="ret-754"/>
			<subtest test_ref="ret-755"/>
		</compound_test>
		<compound_test id="cmp-502" comment="/usr/bin/ppmmix is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-756"/>
			<subtest test_ref="ret-757"/>
			<subtest test_ref="ret-758"/>
		</compound_test>
		<compound_test id="cmp-503" comment="/usr/bin/ppmnorm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-759"/>
			<subtest test_ref="ret-760"/>
			<subtest test_ref="ret-761"/>
		</compound_test>
		<compound_test id="cmp-504" comment="/usr/bin/ppmntsc is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-762"/>
			<subtest test_ref="ret-763"/>
			<subtest test_ref="ret-764"/>
		</compound_test>
		<compound_test id="cmp-505" comment="/usr/bin/ppmpat is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-765"/>
			<subtest test_ref="ret-766"/>
			<subtest test_ref="ret-767"/>
		</compound_test>
		<compound_test id="cmp-506" comment="/usr/bin/ppmquant is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-768"/>
			<subtest test_ref="ret-769"/>
			<subtest test_ref="ret-770"/>
		</compound_test>
		<compound_test id="cmp-507" comment="/usr/bin/ppmqvga is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-771"/>
			<subtest test_ref="ret-772"/>
			<subtest test_ref="ret-773"/>
		</compound_test>
		<compound_test id="cmp-508" comment="/usr/bin/ppmrelief is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-774"/>
			<subtest test_ref="ret-775"/>
			<subtest test_ref="ret-776"/>
		</compound_test>
		<compound_test id="cmp-509" comment="/usr/bin/ppmshift is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-777"/>
			<subtest test_ref="ret-778"/>
			<subtest test_ref="ret-779"/>
		</compound_test>
		<compound_test id="cmp-51" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.119">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wft-107"/>
		</compound_test>
		<compound_test id="cmp-510" comment="/usr/bin/ppmspread is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-780"/>
			<subtest test_ref="ret-781"/>
			<subtest test_ref="ret-782"/>
		</compound_test>
		<compound_test id="cmp-511" comment="/usr/bin/ppmtoacad is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-783"/>
			<subtest test_ref="ret-784"/>
			<subtest test_ref="ret-785"/>
		</compound_test>
		<compound_test id="cmp-512" comment="/usr/bin/ppmtobmp is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-786"/>
			<subtest test_ref="ret-787"/>
			<subtest test_ref="ret-788"/>
		</compound_test>
		<compound_test id="cmp-513" comment="/usr/bin/ppmtoeyuv is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-789"/>
			<subtest test_ref="ret-790"/>
			<subtest test_ref="ret-791"/>
		</compound_test>
		<compound_test id="cmp-514" comment="/usr/bin/ppmtogif is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-792"/>
			<subtest test_ref="ret-793"/>
			<subtest test_ref="ret-794"/>
		</compound_test>
		<compound_test id="cmp-515" comment="/usr/bin/ppmtoicr is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-795"/>
			<subtest test_ref="ret-796"/>
			<subtest test_ref="ret-797"/>
		</compound_test>
		<compound_test id="cmp-516" comment="/usr/bin/ppmtoilbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-798"/>
			<subtest test_ref="ret-799"/>
			<subtest test_ref="ret-800"/>
		</compound_test>
		<compound_test id="cmp-517" comment="/usr/bin/ppmtojpeg is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-801"/>
			<subtest test_ref="ret-802"/>
			<subtest test_ref="ret-803"/>
		</compound_test>
		<compound_test id="cmp-518" comment="/usr/bin/ppmtoleaf is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-804"/>
			<subtest test_ref="ret-805"/>
			<subtest test_ref="ret-806"/>
		</compound_test>
		<compound_test id="cmp-519" comment="/usr/bin/ppmtolj is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-807"/>
			<subtest test_ref="ret-808"/>
			<subtest test_ref="ret-809"/>
		</compound_test>
		<compound_test id="cmp-52" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1274">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-109"/>
		</compound_test>
		<compound_test id="cmp-520" comment="/usr/bin/ppmtomitsu is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-810"/>
			<subtest test_ref="ret-811"/>
			<subtest test_ref="ret-812"/>
		</compound_test>
		<compound_test id="cmp-521" comment="/usr/bin/ppmtompeg is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-813"/>
			<subtest test_ref="ret-814"/>
			<subtest test_ref="ret-815"/>
		</compound_test>
		<compound_test id="cmp-522" comment="/usr/bin/ppmtoneo is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-816"/>
			<subtest test_ref="ret-817"/>
			<subtest test_ref="ret-818"/>
		</compound_test>
		<compound_test id="cmp-523" comment="/usr/bin/ppmtopcx is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-819"/>
			<subtest test_ref="ret-820"/>
			<subtest test_ref="ret-821"/>
		</compound_test>
		<compound_test id="cmp-524" comment="/usr/bin/ppmtopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-822"/>
			<subtest test_ref="ret-823"/>
			<subtest test_ref="ret-824"/>
		</compound_test>
		<compound_test id="cmp-525" comment="/usr/bin/ppmtopi1 is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-825"/>
			<subtest test_ref="ret-826"/>
			<subtest test_ref="ret-827"/>
		</compound_test>
		<compound_test id="cmp-526" comment="/usr/bin/ppmtopict is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-828"/>
			<subtest test_ref="ret-829"/>
			<subtest test_ref="ret-830"/>
		</compound_test>
		<compound_test id="cmp-527" comment="/usr/bin/ppmtopj is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-831"/>
			<subtest test_ref="ret-832"/>
			<subtest test_ref="ret-833"/>
		</compound_test>
		<compound_test id="cmp-528" comment="/usr/bin/ppmtopjxl is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-834"/>
			<subtest test_ref="ret-835"/>
			<subtest test_ref="ret-836"/>
		</compound_test>
		<compound_test id="cmp-529" comment="/usr/bin/ppmtopuzz is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-837"/>
			<subtest test_ref="ret-838"/>
			<subtest test_ref="ret-839"/>
		</compound_test>
		<compound_test id="cmp-53" comment="a vulnerable version of msasn1.dll exists">
			<operation>OR</operation>
			<subtest test_ref="cmp-51"/>
			<subtest test_ref="cmp-52"/>
		</compound_test>
		<compound_test id="cmp-530" comment="/usr/bin/ppmtorgb3 is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-840"/>
			<subtest test_ref="ret-841"/>
			<subtest test_ref="ret-842"/>
		</compound_test>
		<compound_test id="cmp-531" comment="/usr/bin/ppmtosixel is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-843"/>
			<subtest test_ref="ret-844"/>
			<subtest test_ref="ret-845"/>
		</compound_test>
		<compound_test id="cmp-532" comment="/usr/bin/ppmtotga is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-846"/>
			<subtest test_ref="ret-847"/>
			<subtest test_ref="ret-848"/>
		</compound_test>
		<compound_test id="cmp-533" comment="/usr/bin/ppmtouil is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-849"/>
			<subtest test_ref="ret-850"/>
			<subtest test_ref="ret-851"/>
		</compound_test>
		<compound_test id="cmp-534" comment="/usr/bin/ppmtowinicon is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-852"/>
			<subtest test_ref="ret-853"/>
			<subtest test_ref="ret-854"/>
		</compound_test>
		<compound_test id="cmp-535" comment="/usr/bin/ppmtoxpm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-855"/>
			<subtest test_ref="ret-856"/>
			<subtest test_ref="ret-857"/>
		</compound_test>
		<compound_test id="cmp-536" comment="/usr/bin/ppmtoyuv is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-858"/>
			<subtest test_ref="ret-859"/>
			<subtest test_ref="ret-860"/>
		</compound_test>
		<compound_test id="cmp-537" comment="/usr/bin/ppmtoyuvsplit is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-861"/>
			<subtest test_ref="ret-862"/>
			<subtest test_ref="ret-863"/>
		</compound_test>
		<compound_test id="cmp-538" comment="/usr/bin/ppmtv is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-864"/>
			<subtest test_ref="ret-865"/>
			<subtest test_ref="ret-866"/>
		</compound_test>
		<compound_test id="cmp-539" comment="/usr/bin/psidtopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-867"/>
			<subtest test_ref="ret-868"/>
			<subtest test_ref="ret-869"/>
		</compound_test>
		<compound_test id="cmp-54" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed">
			<operation>OR</operation>
			<subtest test_ref="spt-10"/>
			<subtest test_ref="spt-11"/>
			<subtest test_ref="sut-204"/>
		</compound_test>
		<compound_test id="cmp-540" comment="/usr/bin/pstopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-870"/>
			<subtest test_ref="ret-871"/>
			<subtest test_ref="ret-872"/>
		</compound_test>
		<compound_test id="cmp-541" comment="/usr/bin/qrttoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-873"/>
			<subtest test_ref="ret-874"/>
			<subtest test_ref="ret-875"/>
		</compound_test>
		<compound_test id="cmp-542" comment="/usr/bin/rasttopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-876"/>
			<subtest test_ref="ret-877"/>
			<subtest test_ref="ret-878"/>
		</compound_test>
		<compound_test id="cmp-543" comment="/usr/bin/rawtopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-879"/>
			<subtest test_ref="ret-880"/>
			<subtest test_ref="ret-881"/>
		</compound_test>
		<compound_test id="cmp-544" comment="/usr/bin/rawtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-882"/>
			<subtest test_ref="ret-883"/>
			<subtest test_ref="ret-884"/>
		</compound_test>
		<compound_test id="cmp-545" comment="/usr/bin/rgb3toppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-885"/>
			<subtest test_ref="ret-886"/>
			<subtest test_ref="ret-887"/>
		</compound_test>
		<compound_test id="cmp-546" comment="/usr/bin/rletopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-888"/>
			<subtest test_ref="ret-889"/>
			<subtest test_ref="ret-890"/>
		</compound_test>
		<compound_test id="cmp-547" comment="/usr/bin/sbigtopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-891"/>
			<subtest test_ref="ret-892"/>
			<subtest test_ref="ret-893"/>
		</compound_test>
		<compound_test id="cmp-548" comment="/usr/bin/sgitopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-894"/>
			<subtest test_ref="ret-895"/>
			<subtest test_ref="ret-896"/>
		</compound_test>
		<compound_test id="cmp-549" comment="/usr/bin/sirtopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-897"/>
			<subtest test_ref="ret-898"/>
			<subtest test_ref="ret-899"/>
		</compound_test>
		<compound_test id="cmp-550" comment="/usr/bin/sldtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-900"/>
			<subtest test_ref="ret-901"/>
			<subtest test_ref="ret-902"/>
		</compound_test>
		<compound_test id="cmp-551" comment="/usr/bin/spctoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-903"/>
			<subtest test_ref="ret-904"/>
			<subtest test_ref="ret-905"/>
		</compound_test>
		<compound_test id="cmp-552" comment="/usr/bin/spottopgm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-906"/>
			<subtest test_ref="ret-907"/>
			<subtest test_ref="ret-908"/>
		</compound_test>
		<compound_test id="cmp-553" comment="/usr/bin/sputoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-909"/>
			<subtest test_ref="ret-910"/>
			<subtest test_ref="ret-911"/>
		</compound_test>
		<compound_test id="cmp-554" comment="/usr/bin/tgatoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-912"/>
			<subtest test_ref="ret-913"/>
			<subtest test_ref="ret-914"/>
		</compound_test>
		<compound_test id="cmp-555" comment="/usr/bin/thinkjettopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-915"/>
			<subtest test_ref="ret-916"/>
			<subtest test_ref="ret-917"/>
		</compound_test>
		<compound_test id="cmp-556" comment="/usr/bin/tifftopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-918"/>
			<subtest test_ref="ret-919"/>
			<subtest test_ref="ret-920"/>
		</compound_test>
		<compound_test id="cmp-557" comment="/usr/bin/wbmptopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-921"/>
			<subtest test_ref="ret-922"/>
			<subtest test_ref="ret-923"/>
		</compound_test>
		<compound_test id="cmp-558" comment="/usr/bin/winicontoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-924"/>
			<subtest test_ref="ret-925"/>
			<subtest test_ref="ret-926"/>
		</compound_test>
		<compound_test id="cmp-559" comment="/usr/bin/xbmtopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-927"/>
			<subtest test_ref="ret-928"/>
			<subtest test_ref="ret-929"/>
		</compound_test>
		<compound_test id="cmp-56" comment="Inetd running and inetd.conf contains smbd">
			<operation>AND</operation>
			<subtest test_ref="sct-201"/>
			<subtest test_ref="sit-2"/>
		</compound_test>
		<compound_test id="cmp-560" comment="/usr/bin/ximtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-930"/>
			<subtest test_ref="ret-931"/>
			<subtest test_ref="ret-932"/>
		</compound_test>
		<compound_test id="cmp-561" comment="/usr/bin/xpmtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-933"/>
			<subtest test_ref="ret-934"/>
			<subtest test_ref="ret-935"/>
		</compound_test>
		<compound_test id="cmp-562" comment="/usr/bin/xvminitoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-936"/>
			<subtest test_ref="ret-937"/>
			<subtest test_ref="ret-938"/>
		</compound_test>
		<compound_test id="cmp-563" comment="/usr/bin/xwdtopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-939"/>
			<subtest test_ref="ret-940"/>
			<subtest test_ref="ret-941"/>
		</compound_test>
		<compound_test id="cmp-564" comment="/usr/bin/ybmtopbm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-942"/>
			<subtest test_ref="ret-943"/>
			<subtest test_ref="ret-944"/>
		</compound_test>
		<compound_test id="cmp-565" comment="/usr/bin/yuvsplittoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-945"/>
			<subtest test_ref="ret-946"/>
			<subtest test_ref="ret-947"/>
		</compound_test>
		<compound_test id="cmp-566" comment="/usr/bin/yuvtoppm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-948"/>
			<subtest test_ref="ret-949"/>
			<subtest test_ref="ret-950"/>
		</compound_test>
		<compound_test id="cmp-567" comment="/usr/bin/zeisstopnm is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-951"/>
			<subtest test_ref="ret-952"/>
			<subtest test_ref="ret-953"/>
		</compound_test>
		<compound_test id="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
			<operation>AND</operation>
			<subtest test_ref="ret-954"/>
			<subtest test_ref="cmp-569"/>
		</compound_test>
		<compound_test id="cmp-569" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
			<operation>OR</operation>
			<subtest test_ref="ret-955"/>
			<subtest test_ref="ret-956"/>
		</compound_test>
		<compound_test id="cmp-574" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-262"/>
			<subtest test_ref="rvt-263"/>
			<subtest test_ref="rvt-264"/>
		</compound_test>
		<compound_test id="cmp-59" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server">
			<operation>AND</operation>
			<subtest test_ref="wrt-162"/>
			<subtest test_ref="cmp-60"/>
		</compound_test>
		<compound_test id="cmp-6" comment="64-bit version of Windows and rpcrt4.dll is less than 5.1.2600.1361">
			<operation>AND</operation>
			<subtest test_ref="wrt-70"/>
			<subtest test_ref="wft-188"/>
		</compound_test>
		<compound_test id="cmp-60" comment="Windows 2000 Server is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="cmp-50"/>
		</compound_test>
		<compound_test id="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="wrt-28"/>
		</compound_test>
		<compound_test id="cmp-66" comment="Windows XP (sp1 or earlier) is installed">
			<operation>AND</operation>
			<subtest test_ref="wrt-2"/>
			<subtest test_ref="wrt-29"/>
		</compound_test>
		<compound_test id="cmp-68" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed">
			<operation>AND</operation>
			<subtest test_ref="wft-45"/>
			<subtest test_ref="wft-30"/>
		</compound_test>
		<compound_test id="cmp-7" comment="DCOM is enabled on systems with SP3 or later">
			<operation>AND</operation>
			<subtest test_ref="wrt-224"/>
			<subtest test_ref="wrt-283"/>
		</compound_test>
		<compound_test id="cmp-75" comment="ActiveX controls are enabled">
			<operation>OR</operation>
			<subtest test_ref="cmp-92"/>
			<subtest test_ref="cmp-93"/>
		</compound_test>
		<compound_test id="cmp-76" comment="active scripting is enabled">
			<operation>OR</operation>
			<subtest test_ref="cmp-94"/>
			<subtest test_ref="cmp-95"/>
		</compound_test>
		<compound_test id="cmp-77" comment="Windows NT, 2000, or XP is installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-77"/>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="wrt-2"/>
		</compound_test>
		<compound_test id="cmp-78" comment="Windows 2000, XP, or 2003 is installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-1"/>
			<subtest test_ref="wrt-2"/>
			<subtest test_ref="wrt-61"/>
		</compound_test>
		<compound_test id="cmp-8" comment="Windows NT 4.0 Server or Terminal Server is installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-77"/>
			<subtest test_ref="cmp-9"/>
		</compound_test>
		<compound_test id="cmp-802" comment="/usr/bin/gaim is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-960"/>
			<subtest test_ref="ret-961"/>
			<subtest test_ref="ret-962"/>
		</compound_test>
		<compound_test id="cmp-805" comment="/usr/bin/slocate is setgid">
			<operation>AND</operation>
			<subtest test_ref="ret-963"/>
			<subtest test_ref="ret-964"/>
		</compound_test>
		<compound_test id="cmp-806" comment="/usr/bin/mc is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-965"/>
			<subtest test_ref="ret-966"/>
			<subtest test_ref="ret-967"/>
		</compound_test>
		<compound_test id="cmp-808" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-271"/>
			<subtest test_ref="rvt-272"/>
			<subtest test_ref="rvt-273"/>
		</compound_test>
		<compound_test id="cmp-815" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-278"/>
			<subtest test_ref="rvt-279"/>
			<subtest test_ref="rvt-280"/>
		</compound_test>
		<compound_test id="cmp-816" comment="Vulnerable Configuration">
			<operation>OR</operation>
			<subtest test_ref="rvt-281"/>
			<subtest test_ref="rvt-282"/>
			<subtest test_ref="rvt-283"/>
		</compound_test>
		<compound_test id="cmp-821" comment="Vulnerable configuration">
			<operation>OR</operation>
			<subtest test_ref="rvt-285"/>
			<subtest test_ref="rvt-286"/>
			<subtest test_ref="rvt-287"/>
		</compound_test>
		<compound_test id="cmp-822" comment="Vulnerable configuration">
			<operation>OR</operation>
			<subtest test_ref="rvt-288"/>
			<subtest test_ref="rvt-289"/>
			<subtest test_ref="rvt-290"/>
		</compound_test>
		<compound_test id="cmp-823" comment="/usr/sbin/tcpdump is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-971"/>
			<subtest test_ref="ret-972"/>
			<subtest test_ref="ret-973"/>
		</compound_test>
		<compound_test id="cmp-829" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-295"/>
			<subtest test_ref="rvt-296"/>
		</compound_test>
		<compound_test id="cmp-830" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="cmp-831"/>
			<subtest test_ref="cmp-832"/>
			<subtest test_ref="cmp-833"/>
		</compound_test>
		<compound_test id="cmp-831" comment="/usr/bin/ethereal is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-975"/>
			<subtest test_ref="ret-976"/>
			<subtest test_ref="ret-977"/>
		</compound_test>
		<compound_test id="cmp-832" comment="/usr/sbin/ethereal is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-978"/>
			<subtest test_ref="ret-979"/>
			<subtest test_ref="ret-980"/>
		</compound_test>
		<compound_test id="cmp-833" comment="/usr/sbin/tethereal is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-981"/>
			<subtest test_ref="ret-982"/>
			<subtest test_ref="ret-983"/>
		</compound_test>
		<compound_test id="cmp-839" comment="/usr/share/services/kfile_vcf.desktop is readable">
			<operation>OR</operation>
			<subtest test_ref="ret-984"/>
			<subtest test_ref="ret-985"/>
			<subtest test_ref="ret-986"/>
		</compound_test>
		<compound_test id="cmp-840" comment="Vulnerable Configuration">
			<operation>OR</operation>
			<subtest test_ref="rvt-298"/>
			<subtest test_ref="rvt-299"/>
			<subtest test_ref="rvt-300"/>
		</compound_test>
		<compound_test id="cmp-843" comment="Vulnerable Configuration">
			<operation>OR</operation>
			<subtest test_ref="rvt-307"/>
			<subtest test_ref="rvt-308"/>
			<subtest test_ref="rvt-309"/>
		</compound_test>
		<compound_test id="cmp-844" comment="/usr/bin/mozilla is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-987"/>
			<subtest test_ref="ret-988"/>
			<subtest test_ref="ret-989"/>
		</compound_test>
		<compound_test id="cmp-848" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-326"/>
			<subtest test_ref="rvt-327"/>
		</compound_test>
		<compound_test id="cmp-849" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="cmp-850"/>
			<subtest test_ref="cmp-851"/>
			<subtest test_ref="cmp-852"/>
		</compound_test>
		<compound_test id="cmp-850" comment="/usr/bin/ethereal is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-991"/>
			<subtest test_ref="ret-992"/>
			<subtest test_ref="ret-993"/>
		</compound_test>
		<compound_test id="cmp-851" comment="/usr/sbin/ethereal is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-994"/>
			<subtest test_ref="ret-995"/>
			<subtest test_ref="ret-996"/>
		</compound_test>
		<compound_test id="cmp-852" comment="/usr/bin/tethereal is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-997"/>
			<subtest test_ref="ret-998"/>
			<subtest test_ref="ret-999"/>
		</compound_test>
		<compound_test id="cmp-863" comment="Vulnerable Config">
			<operation>OR</operation>
			<subtest test_ref="rvt-328"/>
			<subtest test_ref="rvt-329"/>
		</compound_test>
		<compound_test id="cmp-89" comment="a vulnerable version of mf3216.dll exists on NT">
			<operation>OR</operation>
			<subtest test_ref="cmp-90"/>
			<subtest test_ref="cmp-91"/>
		</compound_test>
		<compound_test id="cmp-9" comment="Server or Terminal Server product option">
			<operation>OR</operation>
			<subtest test_ref="cmp-50"/>
			<subtest test_ref="wrt-43"/>
		</compound_test>
		<compound_test id="cmp-90" comment="non Terminal Server and mf3216.dll is less than 4.0.1381.7263">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-136"/>
		</compound_test>
		<compound_test id="cmp-901" comment="Internet Explorer 5.5 Installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-348"/>
			<subtest test_ref="wrt-349"/>
			<subtest test_ref="wrt-350"/>
		</compound_test>
		<compound_test id="cmp-902" comment="File Downloads Not Disabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-368"/>
			<subtest test_ref="wrt-369"/>
		</compound_test>
		<compound_test id="cmp-903" comment="Run ActiveX Controls and Plugins Not Disabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-368"/>
			<subtest test_ref="wrt-371"/>
		</compound_test>
		<compound_test id="cmp-904" comment="Affected MDAC versions">
			<operation>AND</operation>
			<subtest test_ref="wrt-375"/>
			<subtest test_ref="wft-314"/>
		</compound_test>
		<compound_test id="cmp-905" comment="a vulnerable version of helpctr.exe exists on XP">
			<operation>OR</operation>
			<subtest test_ref="cmp-906"/>
			<subtest test_ref="cmp-907"/>
		</compound_test>
		<compound_test id="cmp-906" comment="No service pack is installed, 32 bit Edition, and helpctr.exe is less than 5.1.2600.128">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="wft-316"/>
		</compound_test>
		<compound_test id="cmp-907" comment="Affected helpctr.exe versions on Windows XP SP1">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-317"/>
		</compound_test>
		<compound_test id="cmp-908" comment="A vulnerable version of evtgprov.dll exists on XP">
			<operation>OR</operation>
			<subtest test_ref="cmp-909"/>
			<subtest test_ref="cmp-910"/>
		</compound_test>
		<compound_test id="cmp-909" comment="No service pack is installed, 32 bit Edition, and evtgprov.dll is less than 5.1.2600.136">
			<operation>AND</operation>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wrt-72"/>
			<subtest test_ref="wft-318"/>
		</compound_test>
		<compound_test id="cmp-91" comment="NT Terminal Server and mf3216.dll is less than 4.0.1381.33562">
			<operation>AND</operation>
			<subtest test_ref="wrt-43"/>
			<subtest test_ref="wft-137"/>
		</compound_test>
		<compound_test id="cmp-910" comment="Affected evtgprov.dll versions on Windows XP SP1">
			<operation>AND</operation>
			<subtest test_ref="wrt-4"/>
			<subtest test_ref="wft-319"/>
		</compound_test>
		<compound_test id="cmp-912" comment="Affected MDAC versions">
			<operation>OR</operation>
			<subtest test_ref="wft-320"/>
			<subtest test_ref="wft-321"/>
			<subtest test_ref="wrt-382"/>
		</compound_test>
		<compound_test id="cmp-914" comment="affected version of SSL and TLS components for OpenSSL">
			<operation>OR</operation>
			<subtest test_ref="rvt-232"/>
			<subtest test_ref="rvt-233"/>
			<subtest test_ref="rvt-234"/>
			<subtest test_ref="rvt-235"/>
			<subtest test_ref="rvt-236"/>
		</compound_test>
		<compound_test id="cmp-92" comment="current user settings are being used and ActiveX controls are enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-121"/>
		</compound_test>
		<compound_test id="cmp-921" comment="kernel versions">
			<operation>OR</operation>
			<subtest test_ref="rvt-334"/>
			<subtest test_ref="rvt-335"/>
			<subtest test_ref="rvt-336"/>
		</compound_test>
		<compound_test id="cmp-923" comment="/bin/mount is world-executable AND Set-UID">
			<operation>AND</operation>
			<subtest test_ref="ret-1001"/>
			<subtest test_ref="ret-1002"/>
		</compound_test>
		<compound_test id="cmp-924" comment="telnet, rlogin, ssh or kmail is executable">
			<operation>OR</operation>
			<subtest test_ref="cmp-925"/>
			<subtest test_ref="cmp-926"/>
			<subtest test_ref="cmp-927"/>
			<subtest test_ref="cmp-928"/>
			<subtest test_ref="cmp-929"/>
			<subtest test_ref="cmp-930"/>
		</compound_test>
		<compound_test id="cmp-925" comment="/usr/bin/telnet is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1003"/>
			<subtest test_ref="ret-1004"/>
			<subtest test_ref="ret-1005"/>
		</compound_test>
		<compound_test id="cmp-926" comment="/usr/kerberos/bin/telnet is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1006"/>
			<subtest test_ref="ret-1007"/>
			<subtest test_ref="ret-1008"/>
		</compound_test>
		<compound_test id="cmp-927" comment="/usr/bin/rlogin is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1009"/>
			<subtest test_ref="ret-1010"/>
			<subtest test_ref="ret-1011"/>
		</compound_test>
		<compound_test id="cmp-928" comment="/usr/kerberos/bin/rlogin is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1012"/>
			<subtest test_ref="ret-1013"/>
			<subtest test_ref="ret-1014"/>
		</compound_test>
		<compound_test id="cmp-929" comment="/usr/bin/ssh is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1015"/>
			<subtest test_ref="ret-1016"/>
			<subtest test_ref="ret-1017"/>
		</compound_test>
		<compound_test id="cmp-93" comment="local machine settings are being used and ActiveX controls are enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-120"/>
		</compound_test>
		<compound_test id="cmp-930" comment="/usr/bin/kmail is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1018"/>
			<subtest test_ref="ret-1019"/>
			<subtest test_ref="ret-1020"/>
		</compound_test>
		<compound_test id="cmp-931" comment="/usr/bin/cvs is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1021"/>
			<subtest test_ref="ret-1022"/>
			<subtest test_ref="ret-1023"/>
		</compound_test>
		<compound_test id="cmp-932" comment="libpng/libpng-devel is less than 1.2.2-21 or libpng10/libpng-devel less than 1.0.13 is installed">
			<operation>OR</operation>
			<subtest test_ref="rvt-342"/>
			<subtest test_ref="rvt-343"/>
			<subtest test_ref="rvt-344"/>
			<subtest test_ref="rvt-345"/>
		</compound_test>
		<compound_test id="cmp-933" comment="Windows NT or 2000 Installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-77"/>
			<subtest test_ref="wrt-1"/>
		</compound_test>
		<compound_test id="cmp-934" comment="NetBIOS enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-393"/>
			<subtest test_ref="wrt-394"/>
			<subtest test_ref="wrt-395"/>
		</compound_test>
		<compound_test id="cmp-937" comment="OpenOffice Permissions">
			<operation>OR</operation>
			<subtest test_ref="cmp-938"/>
			<subtest test_ref="cmp-939"/>
			<subtest test_ref="cmp-940"/>
			<subtest test_ref="cmp-941"/>
			<subtest test_ref="cmp-942"/>
		</compound_test>
		<compound_test id="cmp-938" comment="/usr/bin/oocalc is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1028"/>
			<subtest test_ref="ret-1029"/>
			<subtest test_ref="ret-1030"/>
		</compound_test>
		<compound_test id="cmp-939" comment="/usr/bin/oodraw is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1031"/>
			<subtest test_ref="ret-1032"/>
			<subtest test_ref="ret-1033"/>
		</compound_test>
		<compound_test id="cmp-94" comment="current user settings are being used and active scripting is enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-126"/>
		</compound_test>
		<compound_test id="cmp-940" comment="/usr/bin/oofice is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1034"/>
			<subtest test_ref="ret-1035"/>
			<subtest test_ref="ret-1036"/>
		</compound_test>
		<compound_test id="cmp-941" comment="/usr/bin/ooimpress is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1037"/>
			<subtest test_ref="ret-1038"/>
			<subtest test_ref="ret-1039"/>
		</compound_test>
		<compound_test id="cmp-942" comment="/usr/bin/oowriter is executable">
			<operation>OR</operation>
			<subtest test_ref="ret-1040"/>
			<subtest test_ref="ret-1041"/>
			<subtest test_ref="ret-1042"/>
		</compound_test>
		<compound_test id="cmp-943" comment="Windows 95, 98, NT or 2000 is installed">
			<operation>OR</operation>
			<subtest test_ref="wrt-396"/>
			<subtest test_ref="cmp-933"/>
		</compound_test>
		<compound_test id="cmp-944" comment="This is an NT Terminal Server and the version of Ntoskrnl.exe is less than 4.0.1381.33563">
			<operation>AND</operation>
			<subtest test_ref="wft-344"/>
			<subtest test_ref="wrt-43"/>
		</compound_test>
		<compound_test id="cmp-946" comment="No service pack is installed and the version of Ipnathlp.dll is less than 5.1.2600.137">
			<operation>AND</operation>
			<subtest test_ref="wft-346"/>
			<subtest test_ref="wrt-3"/>
		</compound_test>
		<compound_test id="cmp-947" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364 and windows service pack 1 is installed">
			<operation>AND</operation>
			<subtest test_ref="wft-347"/>
			<subtest test_ref="wrt-4"/>
		</compound_test>
		<compound_test id="cmp-948" comment="64 bit version of windows with service pack 1 installed and the version of Ipnathlp.dll is less than 5.1.2600.1364">
			<operation>AND</operation>
			<subtest test_ref="cmp-947"/>
			<subtest test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-949" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and a 64 bit version of Windows is installed">
			<operation>AND</operation>
			<subtest test_ref="wft-348"/>
			<subtest test_ref="wrt-70"/>
		</compound_test>
		<compound_test id="cmp-95" comment="local machine settings are being used and active scripting is enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-125"/>
		</compound_test>
		<compound_test id="cmp-951" comment="The version of Ipnathlp.dll is less than 5.2.3790.142 and a 32-bit version of Windows is installed">
			<operation>AND</operation>
			<subtest test_ref="wft-348"/>
			<subtest test_ref="wrt-72"/>
		</compound_test>
		<compound_test id="cmp-952" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and 64-bit or 32-bit version of Windows is installed">
			<operation>OR</operation>
			<subtest test_ref="cmp-949"/>
			<subtest test_ref="cmp-951"/>
		</compound_test>
		<compound_test id="cmp-961" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed on XP Gold">
			<operation>AND</operation>
			<subtest test_ref="wft-360"/>
			<subtest test_ref="wrt-3"/>
			<subtest test_ref="wrt-404"/>
			<subtest test_ref="wrt-407"/>
		</compound_test>
		<compound_test id="cmp-962" comment="DirectX 8.2 without DirectX82-KB839643-x86-ENU.EXE Installed">
			<operation>AND</operation>
			<subtest test_ref="wft-362"/>
			<subtest test_ref="wrt-405"/>
			<subtest test_ref="wrt-408"/>
		</compound_test>
		<compound_test id="cmp-963" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed on XP SP1">
			<operation>AND</operation>
			<subtest test_ref="wft-361"/>
			<subtest test_ref="wrt-404"/>
			<subtest test_ref="wrt-407"/>
			<subtest test_ref="wrt-410"/>
		</compound_test>
		<compound_test id="cmp-964" comment="DirectX 9.0 without DirectX9-KB839643-x86-ENU.EXE Installed">
			<operation>AND</operation>
			<subtest test_ref="wft-363"/>
			<subtest test_ref="wrt-406"/>
			<subtest test_ref="wrt-409"/>
		</compound_test>
		<compound_test id="cmp-965" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed">
			<operation>OR</operation>
			<subtest test_ref="cmp-961"/>
			<subtest test_ref="cmp-963"/>
		</compound_test>
		<compound_test id="cmp-966" comment="DirectX without KB839643 Installed">
			<operation>OR</operation>
			<subtest test_ref="cmp-962"/>
			<subtest test_ref="cmp-964"/>
			<subtest test_ref="cmp-965"/>
		</compound_test>
		<compound_test id="cmp-967" comment="DirectX 8.1 without kb839643 installed">
			<operation>AND</operation>
			<subtest test_ref="wft-364"/>
			<subtest test_ref="wrt-404"/>
			<subtest test_ref="wrt-407"/>
		</compound_test>
		<compound_test id="cmp-968" comment="DirectX 8.1 without WindowsServer2003-KB839643-x86-ENU.EXE Installed">
			<operation>AND</operation>
			<subtest test_ref="wft-365"/>
			<subtest test_ref="wrt-404"/>
			<subtest test_ref="wrt-407"/>
		</compound_test>
		<compound_test id="cmp-969" comment="DirectX without KB839643 Installed on Windows Server 2003">
			<operation>OR</operation>
			<subtest test_ref="cmp-962"/>
			<subtest test_ref="cmp-964"/>
			<subtest test_ref="cmp-968"/>
		</compound_test>
		<compound_test id="cmp-97" comment="ActiveX controls and active scripting are enabled">
			<operation>OR</operation>
			<subtest test_ref="cmp-98"/>
			<subtest test_ref="cmp-99"/>
		</compound_test>
		<compound_test id="cmp-98" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-121"/>
			<subtest test_ref="wrt-126"/>
		</compound_test>
		<compound_test id="cmp-99" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
			<operation>AND</operation>
			<subtest test_ref="wrt-30"/>
			<subtest test_ref="wrt-120"/>
			<subtest test_ref="wrt-125"/>
		</compound_test>
		<process_test id="rct-206" comment="rhnsd is running" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<command operator="pattern match">^.*rhnsd.*$</command>
		</process_test>
		<permission_test id="ret-1001" comment="/bin/mount is world-executable AND Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/bin/mount
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1002" comment="/bin/mount is world-executable AND Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/bin/mount
				</path>
				<suid datatype="int" operator="equals">1</suid>
		</permission_test>
		<permission_test id="ret-1003" comment="/usr/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/telnet
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1004" comment="/usr/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/telnet
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1005" comment="/usr/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/telnet
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1006" comment="/usr/kerberos/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/kerberos/bin/telnet
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1007" comment="/usr/kerberos/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/kerberos/bin/telnet
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1008" comment="/usr/kerberos/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/kerberos/bin/telnet
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1009" comment="/usr/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rlogin
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1010" comment="/usr/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rlogin
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1011" comment="/usr/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rlogin
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1012" comment="/usr/kerberos/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/kerberos/bin/rlogin
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1013" comment="/usr/kerberos/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/kerberos/bin/rlogin
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1014" comment="/usr/kerberos/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/kerberos/bin/rlogin
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1015" comment="/usr/bin/ssh is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ssh
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1016" comment="/usr/bin/ssh is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ssh
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1017" comment="/usr/bin/ssh is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ssh
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1018" comment="/usr/bin/kmail is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/kmail
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1019" comment="/usr/bin/kmail is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/kmail
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1020" comment="/usr/bin/kmail is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/kmail
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1021" comment="/usr/bin/cvs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/cvs
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1022" comment="/usr/bin/cvs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/cvs
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1023" comment="/usr/bin/cvs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/cvs
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1024" comment="/proc/tty/driver/serial is world-readable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/proc/tty/driver/serial
				</path>
				<oread datatype="int" operator="equals">1</oread>
		</permission_test>
		<permission_test id="ret-1025" comment="/proc/tty/driver/ is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/proc/tty/driver/
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1026" comment="/proc/tty/ is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/proc/tty/
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1027" comment="/proc/ is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/proc/
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1028" comment="/usr/bin/oocalc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oocalc
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1029" comment="/usr/bin/oocalc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oocalc
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1030" comment="/usr/bin/oocalc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oocalc
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1031" comment="/usr/bin/oodraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oodraw
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1032" comment="/usr/bin/oodraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oodraw
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1033" comment="/usr/bin/oodraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oodraw
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1034" comment="/usr/bin/oofice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oofice
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1035" comment="/usr/bin/oofice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oofice
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1036" comment="/usr/bin/oofice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oofice
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1037" comment="/usr/bin/ooimpress is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ooimpress
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1038" comment="/usr/bin/ooimpress is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ooimpress
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1039" comment="/usr/bin/ooimpress is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ooimpress
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1040" comment="/usr/bin/oowriter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oowriter
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1041" comment="/usr/bin/oowriter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oowriter
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1042" comment="/usr/bin/oowriter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/oowriter
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1046" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tcpdump
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1047" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tcpdump
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1048" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tcpdump
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1049" comment="/usr/bin/lha is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/lha
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1050" comment="/usr/bin/lha is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/lha
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1051" comment="/usr/bin/lha is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/lha
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-1052" comment="/usr/sbin/utempter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/utempter
				</path>
				<sgid datatype="int" operator="equals">1</sgid>
		</permission_test>
		<permission_test id="ret-1053" comment="/usr/sbin/utempter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/utempter
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-1054" comment="/usr/sbin/utempter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/utempter
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-1055" comment="/usr/sbin/utempter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/utempter
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-201" comment="/usr/bin/balsa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/balsa
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-202" comment="/usr/bin/balsa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/balsa
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-203" comment="/usr/bin/balsa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/balsa
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-227" comment="eog is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/eog
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-228" comment="eog is group-executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/eog
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-229" comment="eog is owner-executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/eog
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-238" comment="/usr/bin/gs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gs
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-239" comment="/usr/bin/gs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gs
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-240" comment="/usr/bin/gs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gs
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-241" comment="/usr/bin/gnupg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gnupg
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-242" comment="/usr/bin/gnupg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gnupg
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-243" comment="/usr/bin/evolution is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/evolution
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-244" comment="/usr/bin/evolution is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/evolution
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-245" comment="/usr/bin/evolution is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/evolution
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-249" comment="/usr/bin/kdm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/kdm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-250" comment="/usr/bin/kdm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/kdm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-251" comment="/usr/bin/kdm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/kdm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-252" comment="/usr/bin/konqueror is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/konqueror
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-253" comment="/usr/bin/konqueror is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/konqueror
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-254" comment="/usr/bin/konqueror is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/konqueror
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-255" comment="psbanner is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/libexec/filters/psbanner
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-256" comment="/usr/bin/mutt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mutt
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-257" comment="/usr/bin/mutt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mutt
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-258" comment="/usr/bin/mutt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mutt
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-259" comment="/usr/bin/pine is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pine
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-260" comment="/usr/bin/pine is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pine
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-261" comment="/usr/bin/pine is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pine
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-262" comment="/usr/bin/emacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/emacs
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-263" comment="/usr/bin/emacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/emacs
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-264" comment="/usr/bin/emacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/emacs
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-265" comment="/usr/bin/xemacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xemacs
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-266" comment="/usr/bin/xemacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xemacs
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-267" comment="/usr/bin/xemacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xemacs
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-268" comment="sendmail is Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/sendmail.sendmail
				</path>
				<suid datatype="int" operator="equals">1</suid>
		</permission_test>
		<permission_test id="ret-269" comment="sendmail is Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/sendmail.sendmail
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-270" comment="sendmail is Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/sendmail.sendmail
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-271" comment="sendmail is Set-GID" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/sendmail.sendmail
				</path>
				<sgid datatype="int" operator="equals">1</sgid>
		</permission_test>
		<permission_test id="ret-272" comment="/usr/bin/unzip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/unzip
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-273" comment="/usr/bin/unzip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/unzip
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-274" comment="/usr/bin/unzip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/unzip
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-275" comment="xpdf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xpdf
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-276" comment="xpdf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xpdf
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-277" comment="xpdf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xpdf
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-279" comment="/usr/bin/411toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/411toppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-280" comment="/usr/bin/411toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/411toppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-281" comment="/usr/bin/411toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/411toppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-282" comment="/usr/bin/asciitopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/asciitopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-283" comment="/usr/bin/asciitopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/asciitopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-284" comment="/usr/bin/asciitopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/asciitopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-285" comment="/usr/bin/atktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/atktopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-286" comment="/usr/bin/atktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/atktopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-287" comment="/usr/bin/atktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/atktopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-288" comment="/usr/bin/bioradtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/bioradtopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-289" comment="/usr/bin/bioradtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/bioradtopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-290" comment="/usr/bin/bioradtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/bioradtopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-291" comment="/usr/bin/bmptoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/bmptoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-292" comment="/usr/bin/bmptoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/bmptoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-293" comment="/usr/bin/bmptoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/bmptoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-294" comment="/usr/bin/brushtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/brushtopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-295" comment="/usr/bin/brushtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/brushtopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-296" comment="/usr/bin/brushtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/brushtopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-297" comment="/usr/bin/cmuwmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/cmuwmtopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-298" comment="/usr/bin/cmuwmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/cmuwmtopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-299" comment="/usr/bin/cmuwmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/cmuwmtopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-300" comment="/usr/bin/eyuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/eyuvtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-301" comment="/usr/bin/eyuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/eyuvtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-302" comment="/usr/bin/eyuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/eyuvtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-303" comment="/usr/bin/fiascotopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fiascotopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-304" comment="/usr/bin/fiascotopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fiascotopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-305" comment="/usr/bin/fiascotopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fiascotopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-306" comment="/usr/bin/fitstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fitstopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-307" comment="/usr/bin/fitstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fitstopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-308" comment="/usr/bin/fitstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fitstopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-309" comment="/usr/bin/fstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fstopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-310" comment="/usr/bin/fstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fstopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-311" comment="/usr/bin/fstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/fstopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-312" comment="/usr/bin/g3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/g3topbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-313" comment="/usr/bin/g3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/g3topbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-314" comment="/usr/bin/g3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/g3topbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-315" comment="/usr/bin/gemtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gemtopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-316" comment="/usr/bin/gemtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gemtopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-317" comment="/usr/bin/gemtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gemtopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-318" comment="/usr/bin/gemtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gemtopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-319" comment="/usr/bin/gemtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gemtopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-320" comment="/usr/bin/gemtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gemtopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-321" comment="/usr/bin/giftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/giftopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-322" comment="/usr/bin/giftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/giftopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-323" comment="/usr/bin/giftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/giftopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-324" comment="/usr/bin/gouldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gouldtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-325" comment="/usr/bin/gouldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gouldtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-326" comment="/usr/bin/gouldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gouldtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-327" comment="/usr/bin/hipstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/hipstopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-328" comment="/usr/bin/hipstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/hipstopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-329" comment="/usr/bin/hipstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/hipstopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-330" comment="/usr/bin/hpcdtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/hpcdtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-331" comment="/usr/bin/hpcdtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/hpcdtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-332" comment="/usr/bin/hpcdtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/hpcdtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-333" comment="/usr/bin/icontopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/icontopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-334" comment="/usr/bin/icontopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/icontopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-335" comment="/usr/bin/icontopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/icontopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-336" comment="/usr/bin/ilbmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ilbmtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-337" comment="/usr/bin/ilbmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ilbmtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-338" comment="/usr/bin/ilbmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ilbmtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-339" comment="/usr/bin/imgtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/imgtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-340" comment="/usr/bin/imgtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/imgtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-341" comment="/usr/bin/imgtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/imgtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-342" comment="/usr/bin/jpegtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/jpegtopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-343" comment="/usr/bin/jpegtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/jpegtopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-344" comment="/usr/bin/jpegtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/jpegtopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-345" comment="/usr/bin/leaftoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/leaftoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-346" comment="/usr/bin/leaftoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/leaftoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-347" comment="/usr/bin/leaftoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/leaftoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-348" comment="/usr/bin/lispmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/lispmtopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-349" comment="/usr/bin/lispmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/lispmtopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-350" comment="/usr/bin/lispmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/lispmtopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-351" comment="/usr/bin/macptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/macptopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-352" comment="/usr/bin/macptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/macptopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-353" comment="/usr/bin/macptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/macptopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-354" comment="/usr/bin/mdatopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mdatopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-355" comment="/usr/bin/mdatopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mdatopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-356" comment="/usr/bin/mdatopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mdatopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-357" comment="/usr/bin/mgrtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mgrtopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-358" comment="/usr/bin/mgrtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mgrtopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-359" comment="/usr/bin/mgrtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mgrtopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-360" comment="/usr/bin/mtvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mtvtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-361" comment="/usr/bin/mtvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mtvtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-362" comment="/usr/bin/mtvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mtvtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-363" comment="/usr/bin/neotoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/neotoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-364" comment="/usr/bin/neotoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/neotoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-365" comment="/usr/bin/neotoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/neotoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-366" comment="/usr/bin/palmtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/palmtopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-367" comment="/usr/bin/palmtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/palmtopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-368" comment="/usr/bin/palmtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/palmtopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-369" comment="/usr/bin/pamchannel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamchannel
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-370" comment="/usr/bin/pamchannel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamchannel
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-371" comment="/usr/bin/pamchannel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamchannel
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-372" comment="/usr/bin/pamcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamcut
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-373" comment="/usr/bin/pamcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamcut
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-374" comment="/usr/bin/pamcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamcut
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-375" comment="/usr/bin/pamdeinterlace is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamdeinterlace
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-376" comment="/usr/bin/pamdeinterlace is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamdeinterlace
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-377" comment="/usr/bin/pamdeinterlace is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamdeinterlace
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-378" comment="/usr/bin/pamfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamfile
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-379" comment="/usr/bin/pamfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamfile
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-380" comment="/usr/bin/pamfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamfile
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-381" comment="/usr/bin/pamoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamoil
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-382" comment="/usr/bin/pamoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamoil
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-383" comment="/usr/bin/pamoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamoil
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-384" comment="/usr/bin/pamstretch is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamstretch
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-385" comment="/usr/bin/pamstretch is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamstretch
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-386" comment="/usr/bin/pamstretch is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamstretch
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-387" comment="/usr/bin/pamtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamtopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-388" comment="/usr/bin/pamtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamtopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-389" comment="/usr/bin/pamtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pamtopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-390" comment="/usr/bin/pbmclean is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmclean
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-391" comment="/usr/bin/pbmclean is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmclean
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-392" comment="/usr/bin/pbmclean is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmclean
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-393" comment="/usr/bin/pbmlife is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmlife
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-394" comment="/usr/bin/pbmlife is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmlife
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-395" comment="/usr/bin/pbmlife is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmlife
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-396" comment="/usr/bin/pbmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmmake
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-397" comment="/usr/bin/pbmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmmake
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-398" comment="/usr/bin/pbmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmmake
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-399" comment="/usr/bin/pbmmask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmmask
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-400" comment="/usr/bin/pbmmask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmmask
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-401" comment="/usr/bin/pbmmask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmmask
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-402" comment="/usr/bin/pbmpage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmpage
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-403" comment="/usr/bin/pbmpage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmpage
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-404" comment="/usr/bin/pbmpage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmpage
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-405" comment="/usr/bin/pbmpscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmpscale
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-406" comment="/usr/bin/pbmpscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmpscale
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-407" comment="/usr/bin/pbmpscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmpscale
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-408" comment="/usr/bin/pbmreduce is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmreduce
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-409" comment="/usr/bin/pbmreduce is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmreduce
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-410" comment="/usr/bin/pbmreduce is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmreduce
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-411" comment="/usr/bin/pbmtext is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtext
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-412" comment="/usr/bin/pbmtext is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtext
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-413" comment="/usr/bin/pbmtext is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtext
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-414" comment="/usr/bin/pbmto10x is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmto10x
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-415" comment="/usr/bin/pbmto10x is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmto10x
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-416" comment="/usr/bin/pbmto10x is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmto10x
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-417" comment="/usr/bin/pbmto4425 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmto4425
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-418" comment="/usr/bin/pbmto4425 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmto4425
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-419" comment="/usr/bin/pbmto4425 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmto4425
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-420" comment="/usr/bin/pbmtoascii is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoascii
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-421" comment="/usr/bin/pbmtoascii is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoascii
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-422" comment="/usr/bin/pbmtoascii is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoascii
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-423" comment="/usr/bin/pbmtoatk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoatk
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-424" comment="/usr/bin/pbmtoatk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoatk
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-425" comment="/usr/bin/pbmtoatk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoatk
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-426" comment="/usr/bin/pbmtobbnbg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtobbnbg
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-427" comment="/usr/bin/pbmtobbnbg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtobbnbg
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-428" comment="/usr/bin/pbmtobbnbg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtobbnbg
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-429" comment="/usr/bin/pbmtocmuwm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtocmuwm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-430" comment="/usr/bin/pbmtocmuwm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtocmuwm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-431" comment="/usr/bin/pbmtocmuwm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtocmuwm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-432" comment="/usr/bin/pbmtoepsi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoepsi
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-433" comment="/usr/bin/pbmtoepsi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoepsi
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-434" comment="/usr/bin/pbmtoepsi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoepsi
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-435" comment="/usr/bin/pbmtoepson is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoepson
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-436" comment="/usr/bin/pbmtoepson is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoepson
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-437" comment="/usr/bin/pbmtoepson is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoepson
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-438" comment="/usr/bin/pbmtog3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtog3
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-439" comment="/usr/bin/pbmtog3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtog3
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-440" comment="/usr/bin/pbmtog3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtog3
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-441" comment="/usr/bin/pbmtogem is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtogem
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-442" comment="/usr/bin/pbmtogem is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtogem
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-443" comment="/usr/bin/pbmtogem is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtogem
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-444" comment="/usr/bin/pbmtogo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtogo
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-445" comment="/usr/bin/pbmtogo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtogo
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-446" comment="/usr/bin/pbmtogo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtogo
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-447" comment="/usr/bin/pbmtoicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoicon
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-448" comment="/usr/bin/pbmtoicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoicon
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-449" comment="/usr/bin/pbmtoicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoicon
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-450" comment="/usr/bin/pbmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtolj
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-451" comment="/usr/bin/pbmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtolj
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-452" comment="/usr/bin/pbmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtolj
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-453" comment="/usr/bin/pbmtoln03 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoln03
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-454" comment="/usr/bin/pbmtoln03 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoln03
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-455" comment="/usr/bin/pbmtoln03 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoln03
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-456" comment="/usr/bin/pbmtolps is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtolps
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-457" comment="/usr/bin/pbmtolps is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtolps
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-458" comment="/usr/bin/pbmtolps is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtolps
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-459" comment="/usr/bin/pbmtomacp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomacp
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-460" comment="/usr/bin/pbmtomacp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomacp
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-461" comment="/usr/bin/pbmtomacp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomacp
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-462" comment="/usr/bin/pbmtomda is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomda
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-463" comment="/usr/bin/pbmtomda is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomda
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-464" comment="/usr/bin/pbmtomda is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomda
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-465" comment="/usr/bin/pbmtomgr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomgr
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-466" comment="/usr/bin/pbmtomgr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomgr
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-467" comment="/usr/bin/pbmtomgr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtomgr
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-468" comment="/usr/bin/pbmtonokia is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtonokia
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-469" comment="/usr/bin/pbmtonokia is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtonokia
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-470" comment="/usr/bin/pbmtonokia is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtonokia
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-471" comment="/usr/bin/pbmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-472" comment="/usr/bin/pbmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-473" comment="/usr/bin/pbmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-474" comment="/usr/bin/pbmtopi3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopi3
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-475" comment="/usr/bin/pbmtopi3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopi3
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-476" comment="/usr/bin/pbmtopi3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopi3
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-477" comment="/usr/bin/pbmtopk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopk
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-478" comment="/usr/bin/pbmtopk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopk
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-479" comment="/usr/bin/pbmtopk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopk
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-480" comment="/usr/bin/pbmtoplot is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoplot
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-481" comment="/usr/bin/pbmtoplot is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoplot
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-482" comment="/usr/bin/pbmtoplot is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoplot
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-483" comment="/usr/bin/pbmtoppa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoppa
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-484" comment="/usr/bin/pbmtoppa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoppa
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-485" comment="/usr/bin/pbmtoppa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoppa
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-486" comment="/usr/bin/pbmtopsg3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopsg3
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-487" comment="/usr/bin/pbmtopsg3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopsg3
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-488" comment="/usr/bin/pbmtopsg3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtopsg3
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-489" comment="/usr/bin/pbmtoptx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoptx
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-490" comment="/usr/bin/pbmtoptx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoptx
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-491" comment="/usr/bin/pbmtoptx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoptx
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-492" comment="/usr/bin/pbmtowbmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtowbmp
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-493" comment="/usr/bin/pbmtowbmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtowbmp
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-494" comment="/usr/bin/pbmtowbmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtowbmp
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-495" comment="/usr/bin/pbmtox10bm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtox10bm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-496" comment="/usr/bin/pbmtox10bm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtox10bm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-497" comment="/usr/bin/pbmtox10bm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtox10bm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-498" comment="/usr/bin/pbmtoxbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoxbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-499" comment="/usr/bin/pbmtoxbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoxbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-500" comment="/usr/bin/pbmtoxbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoxbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-501" comment="/usr/bin/pbmtoybm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoybm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-502" comment="/usr/bin/pbmtoybm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoybm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-503" comment="/usr/bin/pbmtoybm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtoybm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-504" comment="/usr/bin/pbmtozinc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtozinc
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-505" comment="/usr/bin/pbmtozinc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtozinc
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-506" comment="/usr/bin/pbmtozinc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmtozinc
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-507" comment="/usr/bin/pbmupc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmupc
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-508" comment="/usr/bin/pbmupc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmupc
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-509" comment="/usr/bin/pbmupc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pbmupc
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-510" comment="/usr/bin/pcxtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pcxtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-511" comment="/usr/bin/pcxtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pcxtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-512" comment="/usr/bin/pcxtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pcxtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-513" comment="/usr/bin/pgmbentley is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmbentley
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-514" comment="/usr/bin/pgmbentley is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmbentley
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-515" comment="/usr/bin/pgmbentley is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmbentley
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-516" comment="/usr/bin/pgmcrater is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmcrater
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-517" comment="/usr/bin/pgmcrater is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmcrater
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-518" comment="/usr/bin/pgmcrater is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmcrater
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-519" comment="/usr/bin/pgmedge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmedge
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-520" comment="/usr/bin/pgmedge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmedge
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-521" comment="/usr/bin/pgmedge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmedge
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-522" comment="/usr/bin/pgmenhance is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmenhance
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-523" comment="/usr/bin/pgmenhance is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmenhance
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-524" comment="/usr/bin/pgmenhance is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmenhance
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-525" comment="/usr/bin/pgmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmhist
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-526" comment="/usr/bin/pgmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmhist
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-527" comment="/usr/bin/pgmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmhist
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-528" comment="/usr/bin/pgmkernel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmkernel
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-529" comment="/usr/bin/pgmkernel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmkernel
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-530" comment="/usr/bin/pgmkernel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmkernel
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-531" comment="/usr/bin/pgmnoise is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmnoise
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-532" comment="/usr/bin/pgmnoise is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmnoise
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-533" comment="/usr/bin/pgmnoise is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmnoise
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-534" comment="/usr/bin/pgmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmnorm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-535" comment="/usr/bin/pgmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmnorm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-536" comment="/usr/bin/pgmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmnorm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-537" comment="/usr/bin/pgmoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmoil
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-538" comment="/usr/bin/pgmoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmoil
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-539" comment="/usr/bin/pgmoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmoil
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-540" comment="/usr/bin/pgmramp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmramp
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-541" comment="/usr/bin/pgmramp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmramp
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-542" comment="/usr/bin/pgmramp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmramp
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-543" comment="/usr/bin/pgmslice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmslice
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-544" comment="/usr/bin/pgmslice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmslice
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-545" comment="/usr/bin/pgmslice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmslice
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-546" comment="/usr/bin/pgmtexture is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtexture
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-547" comment="/usr/bin/pgmtexture is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtexture
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-548" comment="/usr/bin/pgmtexture is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtexture
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-549" comment="/usr/bin/pgmtofs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtofs
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-550" comment="/usr/bin/pgmtofs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtofs
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-551" comment="/usr/bin/pgmtofs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtofs
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-552" comment="/usr/bin/pgmtolispm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtolispm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-553" comment="/usr/bin/pgmtolispm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtolispm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-554" comment="/usr/bin/pgmtolispm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtolispm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-555" comment="/usr/bin/pgmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-556" comment="/usr/bin/pgmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-557" comment="/usr/bin/pgmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-558" comment="/usr/bin/pgmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-559" comment="/usr/bin/pgmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-560" comment="/usr/bin/pgmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pgmtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-561" comment="/usr/bin/pi1toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pi1toppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-562" comment="/usr/bin/pi1toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pi1toppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-563" comment="/usr/bin/pi1toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pi1toppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-564" comment="/usr/bin/pi3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pi3topbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-565" comment="/usr/bin/pi3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pi3topbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-566" comment="/usr/bin/pi3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pi3topbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-567" comment="/usr/bin/pjtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pjtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-568" comment="/usr/bin/pjtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pjtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-569" comment="/usr/bin/pjtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pjtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-570" comment="/usr/bin/pktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pktopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-571" comment="/usr/bin/pktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pktopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-572" comment="/usr/bin/pktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pktopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-573" comment="/usr/bin/pngtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pngtopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-574" comment="/usr/bin/pngtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pngtopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-575" comment="/usr/bin/pngtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pngtopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-576" comment="/usr/bin/pnmalias is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmalias
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-577" comment="/usr/bin/pnmalias is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmalias
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-578" comment="/usr/bin/pnmalias is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmalias
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-579" comment="/usr/bin/pnmarith is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmarith
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-580" comment="/usr/bin/pnmarith is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmarith
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-581" comment="/usr/bin/pnmarith is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmarith
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-582" comment="/usr/bin/pnmcat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcat
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-583" comment="/usr/bin/pnmcat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcat
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-584" comment="/usr/bin/pnmcat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcat
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-585" comment="/usr/bin/pnmcolormap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcolormap
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-586" comment="/usr/bin/pnmcolormap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcolormap
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-587" comment="/usr/bin/pnmcolormap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcolormap
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-588" comment="/usr/bin/pnmcomp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcomp
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-589" comment="/usr/bin/pnmcomp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcomp
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-590" comment="/usr/bin/pnmcomp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcomp
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-591" comment="/usr/bin/pnmconvol is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmconvol
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-592" comment="/usr/bin/pnmconvol is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmconvol
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-593" comment="/usr/bin/pnmconvol is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmconvol
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-594" comment="/usr/bin/pnmcrop is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcrop
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-595" comment="/usr/bin/pnmcrop is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcrop
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-596" comment="/usr/bin/pnmcrop is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcrop
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-597" comment="/usr/bin/pnmcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcut
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-598" comment="/usr/bin/pnmcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcut
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-599" comment="/usr/bin/pnmcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmcut
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-600" comment="/usr/bin/pnmdepth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmdepth
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-601" comment="/usr/bin/pnmdepth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmdepth
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-602" comment="/usr/bin/pnmdepth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmdepth
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-603" comment="/usr/bin/pnmenlarge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmenlarge
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-604" comment="/usr/bin/pnmenlarge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmenlarge
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-605" comment="/usr/bin/pnmenlarge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmenlarge
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-606" comment="/usr/bin/pnmfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmfile
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-607" comment="/usr/bin/pnmfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmfile
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-608" comment="/usr/bin/pnmfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmfile
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-609" comment="/usr/bin/pnmflip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmflip
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-610" comment="/usr/bin/pnmflip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmflip
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-611" comment="/usr/bin/pnmflip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmflip
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-612" comment="/usr/bin/pnmgamma is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmgamma
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-613" comment="/usr/bin/pnmgamma is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmgamma
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-614" comment="/usr/bin/pnmgamma is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmgamma
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-615" comment="/usr/bin/pnmhisteq is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmhisteq
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-616" comment="/usr/bin/pnmhisteq is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmhisteq
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-617" comment="/usr/bin/pnmhisteq is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmhisteq
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-618" comment="/usr/bin/pnmhistmap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmhistmap
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-619" comment="/usr/bin/pnmhistmap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmhistmap
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-620" comment="/usr/bin/pnmhistmap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmhistmap
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-621" comment="/usr/bin/pnminterp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnminterp
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-622" comment="/usr/bin/pnminterp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnminterp
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-623" comment="/usr/bin/pnminterp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnminterp
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-624" comment="/usr/bin/pnminvert is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnminvert
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-625" comment="/usr/bin/pnminvert is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnminvert
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-626" comment="/usr/bin/pnminvert is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnminvert
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-627" comment="/usr/bin/pnmmontage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmmontage
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-628" comment="/usr/bin/pnmmontage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmmontage
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-629" comment="/usr/bin/pnmmontage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmmontage
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-630" comment="/usr/bin/pnmnlfilt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmnlfilt
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-631" comment="/usr/bin/pnmnlfilt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmnlfilt
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-632" comment="/usr/bin/pnmnlfilt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmnlfilt
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-633" comment="/usr/bin/pnmnoraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmnoraw
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-634" comment="/usr/bin/pnmnoraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmnoraw
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-635" comment="/usr/bin/pnmnoraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmnoraw
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-636" comment="/usr/bin/pnmpad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpad
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-637" comment="/usr/bin/pnmpad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpad
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-638" comment="/usr/bin/pnmpad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpad
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-639" comment="/usr/bin/pnmpaste is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpaste
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-640" comment="/usr/bin/pnmpaste is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpaste
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-641" comment="/usr/bin/pnmpaste is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpaste
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-642" comment="/usr/bin/pnmpsnr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpsnr
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-643" comment="/usr/bin/pnmpsnr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpsnr
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-644" comment="/usr/bin/pnmpsnr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmpsnr
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-645" comment="/usr/bin/pnmremap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmremap
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-646" comment="/usr/bin/pnmremap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmremap
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-647" comment="/usr/bin/pnmremap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmremap
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-648" comment="/usr/bin/pnmrotate is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmrotate
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-649" comment="/usr/bin/pnmrotate is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmrotate
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-650" comment="/usr/bin/pnmrotate is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmrotate
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-651" comment="/usr/bin/pnmscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmscale
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-652" comment="/usr/bin/pnmscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmscale
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-653" comment="/usr/bin/pnmscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmscale
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-654" comment="/usr/bin/pnmscalefixed is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmscalefixed
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-655" comment="/usr/bin/pnmscalefixed is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmscalefixed
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-656" comment="/usr/bin/pnmscalefixed is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmscalefixed
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-657" comment="/usr/bin/pnmshear is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmshear
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-658" comment="/usr/bin/pnmshear is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmshear
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-659" comment="/usr/bin/pnmshear is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmshear
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-660" comment="/usr/bin/pnmsmooth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmsmooth
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-661" comment="/usr/bin/pnmsmooth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmsmooth
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-662" comment="/usr/bin/pnmsmooth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmsmooth
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-663" comment="/usr/bin/pnmsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmsplit
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-664" comment="/usr/bin/pnmsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmsplit
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-665" comment="/usr/bin/pnmsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmsplit
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-666" comment="/usr/bin/pnmtile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtile
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-667" comment="/usr/bin/pnmtile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtile
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-668" comment="/usr/bin/pnmtile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtile
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-669" comment="/usr/bin/pnmtoddif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoddif
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-670" comment="/usr/bin/pnmtoddif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoddif
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-671" comment="/usr/bin/pnmtoddif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoddif
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-672" comment="/usr/bin/pnmtofiasco is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtofiasco
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-673" comment="/usr/bin/pnmtofiasco is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtofiasco
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-674" comment="/usr/bin/pnmtofiasco is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtofiasco
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-675" comment="/usr/bin/pnmtofits is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtofits
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-676" comment="/usr/bin/pnmtofits is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtofits
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-677" comment="/usr/bin/pnmtofits is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtofits
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-678" comment="/usr/bin/pnmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtojpeg
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-679" comment="/usr/bin/pnmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtojpeg
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-680" comment="/usr/bin/pnmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtojpeg
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-681" comment="/usr/bin/pnmtopalm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtopalm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-682" comment="/usr/bin/pnmtopalm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtopalm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-683" comment="/usr/bin/pnmtopalm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtopalm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-684" comment="/usr/bin/pnmtoplainpnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoplainpnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-685" comment="/usr/bin/pnmtoplainpnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoplainpnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-686" comment="/usr/bin/pnmtoplainpnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoplainpnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-687" comment="/usr/bin/pnmtopng is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtopng
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-688" comment="/usr/bin/pnmtopng is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtopng
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-689" comment="/usr/bin/pnmtopng is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtopng
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-690" comment="/usr/bin/pnmtops is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtops
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-691" comment="/usr/bin/pnmtops is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtops
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-692" comment="/usr/bin/pnmtops is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtops
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-693" comment="/usr/bin/pnmtorast is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtorast
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-694" comment="/usr/bin/pnmtorast is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtorast
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-695" comment="/usr/bin/pnmtorast is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtorast
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-696" comment="/usr/bin/pnmtorle is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtorle
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-697" comment="/usr/bin/pnmtorle is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtorle
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-698" comment="/usr/bin/pnmtorle is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtorle
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-699" comment="/usr/bin/pnmtosgi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtosgi
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-700" comment="/usr/bin/pnmtosgi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtosgi
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-701" comment="/usr/bin/pnmtosgi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtosgi
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-702" comment="/usr/bin/pnmtosir is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtosir
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-703" comment="/usr/bin/pnmtosir is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtosir
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-704" comment="/usr/bin/pnmtosir is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtosir
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-705" comment="/usr/bin/pnmtotiff is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtotiff
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-706" comment="/usr/bin/pnmtotiff is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtotiff
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-707" comment="/usr/bin/pnmtotiff is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtotiff
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-708" comment="/usr/bin/pnmtotiffcmyk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtotiffcmyk
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-709" comment="/usr/bin/pnmtotiffcmyk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtotiffcmyk
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-710" comment="/usr/bin/pnmtotiffcmyk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtotiffcmyk
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-711" comment="/usr/bin/pnmtoxwd is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoxwd
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-712" comment="/usr/bin/pnmtoxwd is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoxwd
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-713" comment="/usr/bin/pnmtoxwd is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pnmtoxwd
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-714" comment="/usr/bin/ppm3d is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppm3d
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-715" comment="/usr/bin/ppm3d is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppm3d
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-716" comment="/usr/bin/ppm3d is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppm3d
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-717" comment="/usr/bin/ppmbrighten is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmbrighten
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-718" comment="/usr/bin/ppmbrighten is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmbrighten
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-719" comment="/usr/bin/ppmbrighten is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmbrighten
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-720" comment="/usr/bin/ppmchange is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmchange
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-721" comment="/usr/bin/ppmchange is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmchange
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-722" comment="/usr/bin/ppmchange is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmchange
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-723" comment="/usr/bin/ppmcie is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcie
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-724" comment="/usr/bin/ppmcie is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcie
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-725" comment="/usr/bin/ppmcie is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcie
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-726" comment="/usr/bin/ppmcolormask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcolormask
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-727" comment="/usr/bin/ppmcolormask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcolormask
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-728" comment="/usr/bin/ppmcolormask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcolormask
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-729" comment="/usr/bin/ppmcolors is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcolors
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-730" comment="/usr/bin/ppmcolors is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcolors
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-731" comment="/usr/bin/ppmcolors is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmcolors
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-732" comment="/usr/bin/ppmdim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdim
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-733" comment="/usr/bin/ppmdim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdim
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-734" comment="/usr/bin/ppmdim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdim
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-735" comment="/usr/bin/ppmdist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdist
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-736" comment="/usr/bin/ppmdist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdist
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-737" comment="/usr/bin/ppmdist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdist
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-738" comment="/usr/bin/ppmdither is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdither
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-739" comment="/usr/bin/ppmdither is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdither
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-740" comment="/usr/bin/ppmdither is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmdither
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-741" comment="/usr/bin/ppmflash is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmflash
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-742" comment="/usr/bin/ppmflash is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmflash
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-743" comment="/usr/bin/ppmflash is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmflash
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-744" comment="/usr/bin/ppmforge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmforge
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-745" comment="/usr/bin/ppmforge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmforge
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-746" comment="/usr/bin/ppmforge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmforge
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-747" comment="/usr/bin/ppmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmhist
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-748" comment="/usr/bin/ppmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmhist
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-749" comment="/usr/bin/ppmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmhist
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-750" comment="/usr/bin/ppmlabel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmlabel
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-751" comment="/usr/bin/ppmlabel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmlabel
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-752" comment="/usr/bin/ppmlabel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmlabel
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-753" comment="/usr/bin/ppmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmmake
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-754" comment="/usr/bin/ppmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmmake
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-755" comment="/usr/bin/ppmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmmake
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-756" comment="/usr/bin/ppmmix is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmmix
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-757" comment="/usr/bin/ppmmix is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmmix
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-758" comment="/usr/bin/ppmmix is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmmix
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-759" comment="/usr/bin/ppmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmnorm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-760" comment="/usr/bin/ppmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmnorm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-761" comment="/usr/bin/ppmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmnorm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-762" comment="/usr/bin/ppmntsc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmntsc
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-763" comment="/usr/bin/ppmntsc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmntsc
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-764" comment="/usr/bin/ppmntsc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmntsc
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-765" comment="/usr/bin/ppmpat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmpat
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-766" comment="/usr/bin/ppmpat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmpat
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-767" comment="/usr/bin/ppmpat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmpat
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-768" comment="/usr/bin/ppmquant is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmquant
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-769" comment="/usr/bin/ppmquant is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmquant
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-770" comment="/usr/bin/ppmquant is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmquant
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-771" comment="/usr/bin/ppmqvga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmqvga
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-772" comment="/usr/bin/ppmqvga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmqvga
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-773" comment="/usr/bin/ppmqvga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmqvga
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-774" comment="/usr/bin/ppmrelief is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmrelief
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-775" comment="/usr/bin/ppmrelief is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmrelief
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-776" comment="/usr/bin/ppmrelief is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmrelief
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-777" comment="/usr/bin/ppmshift is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmshift
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-778" comment="/usr/bin/ppmshift is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmshift
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-779" comment="/usr/bin/ppmshift is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmshift
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-780" comment="/usr/bin/ppmspread is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmspread
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-781" comment="/usr/bin/ppmspread is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmspread
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-782" comment="/usr/bin/ppmspread is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmspread
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-783" comment="/usr/bin/ppmtoacad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoacad
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-784" comment="/usr/bin/ppmtoacad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoacad
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-785" comment="/usr/bin/ppmtoacad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoacad
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-786" comment="/usr/bin/ppmtobmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtobmp
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-787" comment="/usr/bin/ppmtobmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtobmp
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-788" comment="/usr/bin/ppmtobmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtobmp
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-789" comment="/usr/bin/ppmtoeyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoeyuv
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-790" comment="/usr/bin/ppmtoeyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoeyuv
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-791" comment="/usr/bin/ppmtoeyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoeyuv
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-792" comment="/usr/bin/ppmtogif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtogif
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-793" comment="/usr/bin/ppmtogif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtogif
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-794" comment="/usr/bin/ppmtogif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtogif
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-795" comment="/usr/bin/ppmtoicr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoicr
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-796" comment="/usr/bin/ppmtoicr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoicr
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-797" comment="/usr/bin/ppmtoicr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoicr
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-798" comment="/usr/bin/ppmtoilbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoilbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-799" comment="/usr/bin/ppmtoilbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoilbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-800" comment="/usr/bin/ppmtoilbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoilbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-801" comment="/usr/bin/ppmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtojpeg
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-802" comment="/usr/bin/ppmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtojpeg
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-803" comment="/usr/bin/ppmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtojpeg
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-804" comment="/usr/bin/ppmtoleaf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoleaf
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-805" comment="/usr/bin/ppmtoleaf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoleaf
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-806" comment="/usr/bin/ppmtoleaf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoleaf
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-807" comment="/usr/bin/ppmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtolj
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-808" comment="/usr/bin/ppmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtolj
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-809" comment="/usr/bin/ppmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtolj
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-810" comment="/usr/bin/ppmtomitsu is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtomitsu
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-811" comment="/usr/bin/ppmtomitsu is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtomitsu
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-812" comment="/usr/bin/ppmtomitsu is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtomitsu
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-813" comment="/usr/bin/ppmtompeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtompeg
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-814" comment="/usr/bin/ppmtompeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtompeg
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-815" comment="/usr/bin/ppmtompeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtompeg
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-816" comment="/usr/bin/ppmtoneo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoneo
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-817" comment="/usr/bin/ppmtoneo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoneo
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-818" comment="/usr/bin/ppmtoneo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoneo
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-819" comment="/usr/bin/ppmtopcx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopcx
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-820" comment="/usr/bin/ppmtopcx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopcx
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-821" comment="/usr/bin/ppmtopcx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopcx
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-822" comment="/usr/bin/ppmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-823" comment="/usr/bin/ppmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-824" comment="/usr/bin/ppmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-825" comment="/usr/bin/ppmtopi1 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopi1
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-826" comment="/usr/bin/ppmtopi1 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopi1
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-827" comment="/usr/bin/ppmtopi1 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopi1
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-828" comment="/usr/bin/ppmtopict is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopict
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-829" comment="/usr/bin/ppmtopict is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopict
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-830" comment="/usr/bin/ppmtopict is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopict
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-831" comment="/usr/bin/ppmtopj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopj
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-832" comment="/usr/bin/ppmtopj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopj
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-833" comment="/usr/bin/ppmtopj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopj
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-834" comment="/usr/bin/ppmtopjxl is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopjxl
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-835" comment="/usr/bin/ppmtopjxl is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopjxl
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-836" comment="/usr/bin/ppmtopjxl is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopjxl
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-837" comment="/usr/bin/ppmtopuzz is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopuzz
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-838" comment="/usr/bin/ppmtopuzz is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopuzz
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-839" comment="/usr/bin/ppmtopuzz is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtopuzz
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-840" comment="/usr/bin/ppmtorgb3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtorgb3
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-841" comment="/usr/bin/ppmtorgb3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtorgb3
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-842" comment="/usr/bin/ppmtorgb3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtorgb3
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-843" comment="/usr/bin/ppmtosixel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtosixel
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-844" comment="/usr/bin/ppmtosixel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtosixel
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-845" comment="/usr/bin/ppmtosixel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtosixel
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-846" comment="/usr/bin/ppmtotga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtotga
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-847" comment="/usr/bin/ppmtotga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtotga
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-848" comment="/usr/bin/ppmtotga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtotga
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-849" comment="/usr/bin/ppmtouil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtouil
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-850" comment="/usr/bin/ppmtouil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtouil
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-851" comment="/usr/bin/ppmtouil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtouil
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-852" comment="/usr/bin/ppmtowinicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtowinicon
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-853" comment="/usr/bin/ppmtowinicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtowinicon
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-854" comment="/usr/bin/ppmtowinicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtowinicon
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-855" comment="/usr/bin/ppmtoxpm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoxpm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-856" comment="/usr/bin/ppmtoxpm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoxpm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-857" comment="/usr/bin/ppmtoxpm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoxpm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-858" comment="/usr/bin/ppmtoyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoyuv
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-859" comment="/usr/bin/ppmtoyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoyuv
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-860" comment="/usr/bin/ppmtoyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoyuv
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-861" comment="/usr/bin/ppmtoyuvsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoyuvsplit
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-862" comment="/usr/bin/ppmtoyuvsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoyuvsplit
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-863" comment="/usr/bin/ppmtoyuvsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtoyuvsplit
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-864" comment="/usr/bin/ppmtv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtv
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-865" comment="/usr/bin/ppmtv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtv
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-866" comment="/usr/bin/ppmtv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ppmtv
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-867" comment="/usr/bin/psidtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/psidtopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-868" comment="/usr/bin/psidtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/psidtopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-869" comment="/usr/bin/psidtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/psidtopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-870" comment="/usr/bin/pstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pstopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-871" comment="/usr/bin/pstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pstopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-872" comment="/usr/bin/pstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/pstopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-873" comment="/usr/bin/qrttoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/qrttoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-874" comment="/usr/bin/qrttoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/qrttoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-875" comment="/usr/bin/qrttoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/qrttoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-876" comment="/usr/bin/rasttopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rasttopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-877" comment="/usr/bin/rasttopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rasttopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-878" comment="/usr/bin/rasttopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rasttopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-879" comment="/usr/bin/rawtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rawtopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-880" comment="/usr/bin/rawtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rawtopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-881" comment="/usr/bin/rawtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rawtopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-882" comment="/usr/bin/rawtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rawtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-883" comment="/usr/bin/rawtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rawtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-884" comment="/usr/bin/rawtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rawtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-885" comment="/usr/bin/rgb3toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rgb3toppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-886" comment="/usr/bin/rgb3toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rgb3toppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-887" comment="/usr/bin/rgb3toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rgb3toppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-888" comment="/usr/bin/rletopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rletopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-889" comment="/usr/bin/rletopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rletopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-890" comment="/usr/bin/rletopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/rletopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-891" comment="/usr/bin/sbigtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sbigtopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-892" comment="/usr/bin/sbigtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sbigtopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-893" comment="/usr/bin/sbigtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sbigtopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-894" comment="/usr/bin/sgitopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sgitopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-895" comment="/usr/bin/sgitopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sgitopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-896" comment="/usr/bin/sgitopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sgitopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-897" comment="/usr/bin/sirtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sirtopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-898" comment="/usr/bin/sirtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sirtopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-899" comment="/usr/bin/sirtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sirtopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-900" comment="/usr/bin/sldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sldtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-901" comment="/usr/bin/sldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sldtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-902" comment="/usr/bin/sldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sldtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-903" comment="/usr/bin/spctoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/spctoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-904" comment="/usr/bin/spctoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/spctoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-905" comment="/usr/bin/spctoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/spctoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-906" comment="/usr/bin/spottopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/spottopgm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-907" comment="/usr/bin/spottopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/spottopgm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-908" comment="/usr/bin/spottopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/spottopgm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-909" comment="/usr/bin/sputoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sputoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-910" comment="/usr/bin/sputoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sputoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-911" comment="/usr/bin/sputoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/sputoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-912" comment="/usr/bin/tgatoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tgatoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-913" comment="/usr/bin/tgatoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tgatoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-914" comment="/usr/bin/tgatoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tgatoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-915" comment="/usr/bin/thinkjettopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/thinkjettopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-916" comment="/usr/bin/thinkjettopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/thinkjettopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-917" comment="/usr/bin/thinkjettopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/thinkjettopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-918" comment="/usr/bin/tifftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tifftopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-919" comment="/usr/bin/tifftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tifftopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-920" comment="/usr/bin/tifftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tifftopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-921" comment="/usr/bin/wbmptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/wbmptopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-922" comment="/usr/bin/wbmptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/wbmptopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-923" comment="/usr/bin/wbmptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/wbmptopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-924" comment="/usr/bin/winicontoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/winicontoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-925" comment="/usr/bin/winicontoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/winicontoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-926" comment="/usr/bin/winicontoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/winicontoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-927" comment="/usr/bin/xbmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xbmtopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-928" comment="/usr/bin/xbmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xbmtopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-929" comment="/usr/bin/xbmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xbmtopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-930" comment="/usr/bin/ximtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ximtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-931" comment="/usr/bin/ximtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ximtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-932" comment="/usr/bin/ximtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ximtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-933" comment="/usr/bin/xpmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xpmtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-934" comment="/usr/bin/xpmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xpmtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-935" comment="/usr/bin/xpmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xpmtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-936" comment="/usr/bin/xvminitoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xvminitoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-937" comment="/usr/bin/xvminitoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xvminitoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-938" comment="/usr/bin/xvminitoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xvminitoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-939" comment="/usr/bin/xwdtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xwdtopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-940" comment="/usr/bin/xwdtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xwdtopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-941" comment="/usr/bin/xwdtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/xwdtopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-942" comment="/usr/bin/ybmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ybmtopbm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-943" comment="/usr/bin/ybmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ybmtopbm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-944" comment="/usr/bin/ybmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ybmtopbm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-945" comment="/usr/bin/yuvsplittoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/yuvsplittoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-946" comment="/usr/bin/yuvsplittoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/yuvsplittoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-947" comment="/usr/bin/yuvsplittoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/yuvsplittoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-948" comment="/usr/bin/yuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/yuvtoppm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-949" comment="/usr/bin/yuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/yuvtoppm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-950" comment="/usr/bin/yuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/yuvtoppm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-951" comment="/usr/bin/zeisstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/zeisstopnm
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-952" comment="/usr/bin/zeisstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/zeisstopnm
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-953" comment="/usr/bin/zeisstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/zeisstopnm
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-954" comment="/usr/X11R6/bin/XFree86 is SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/X11R6/bin/XFree86
				</path>
				<suid datatype="int" operator="equals">1</suid>
		</permission_test>
		<permission_test id="ret-955" comment="/usr/X11R6/bin/XFree86 is SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/X11R6/bin/XFree86
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-956" comment="/usr/X11R6/bin/XFree86 is SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/X11R6/bin/XFree86
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-960" comment="/usr/bin/gaim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gaim
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-961" comment="/usr/bin/gaim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gaim
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-962" comment="/usr/bin/gaim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/gaim
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-963" comment="/usr/bin/slocate is setgid" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/slocate
				</path>
				<sgid datatype="int" operator="equals">1</sgid>
		</permission_test>
		<permission_test id="ret-964" comment="/usr/bin/slocate is setgid" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/slocate
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-965" comment="/usr/bin/mc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mc
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-966" comment="/usr/bin/mc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mc
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-967" comment="/usr/bin/mc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mc
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-971" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tcpdump
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-972" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tcpdump
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-973" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tcpdump
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-974" comment="/ is world-writable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/
				</path>
				<owrite datatype="int" operator="equals">1</owrite>
		</permission_test>
		<permission_test id="ret-975" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ethereal
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-976" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ethereal
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-977" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ethereal
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-978" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/ethereal
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-979" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/ethereal
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-980" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/ethereal
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-981" comment="/usr/sbin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tethereal
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-982" comment="/usr/sbin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tethereal
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-983" comment="/usr/sbin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/tethereal
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-984" comment="/usr/share/services/kfile_vcf.desktop is readable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/share/services/kfile_vcf.desktop
				</path>
				<uread datatype="int" operator="equals">1</uread>
		</permission_test>
		<permission_test id="ret-985" comment="/usr/share/services/kfile_vcf.desktop is readable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/share/services/kfile_vcf.desktop
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-986" comment="/usr/share/services/kfile_vcf.desktop is readable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/share/services/kfile_vcf.desktop
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-987" comment="/usr/bin/mozilla is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mozilla
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-988" comment="/usr/bin/mozilla is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mozilla
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-989" comment="/usr/bin/mozilla is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/mozilla
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-991" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ethereal
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-992" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ethereal
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-993" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/ethereal
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-994" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/ethereal
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-995" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/ethereal
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-996" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/sbin/ethereal
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="ret-997" comment="/usr/bin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tethereal
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="ret-998" comment="/usr/bin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tethereal
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="ret-999" comment="/usr/bin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					/usr/bin/tethereal
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<file_test id="rft-1" comment="/etc/httpd/modules/libphp4.so exists" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<path datatype="component">
					<component type="literal">/etc/httpd/modules/libphp4.so</component>
				</path>
		</file_test>
		<inetlisteningservers_test id="rlt-201" comment="cupsd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*cupsd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-202" comment="httpd listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*httpd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-203" comment="httpd.worker is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*httpd\.worker.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-204" comment="lpd listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*lpd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-205" comment="mysqld is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*mysqld.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-206" comment="rpc.mountd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*rpc\.mountd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-207" comment="sshd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*sshd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-208" comment="smtpd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*smtpd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-209" comment="smbd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*smbd.*</program_name>
				<protocol operator="equals">TCP</protocol>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-210" comment="smbd is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*smbd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-211" comment="sendmail listening" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*sendmail.*</program_name>
				<protocol operator="equals">TCP</protocol>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-212" comment="sendmail is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*sendmail.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-213" comment="vsftpd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*vsftpd.*</program_name>
				<protocol operator="equals">TCP</protocol>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-214" comment="xinetd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*xinetd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-215" comment="ypserv is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*ypserv.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-217" comment="a program is listening on TCP or UDP port 1720" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<local_port datatype="int" operator="equals">1720</local_port>				
				<program_name operator="pattern match">.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-218" comment="httpd is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*httpd.*</program_name>
				<protocol operator="equals">TCP</protocol>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-220" comment="httpd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*httpd</program_name>
				<protocol operator="equals">TCP</protocol>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-221" comment="rpc.mountd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*rpc\.mountd</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-223" comment="snmpd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*snmpd.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-225" comment="squid is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*squid.*</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-230" comment="racoon is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*racoon</program_name>
				<protocol operator="equals">UDP</protocol>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-233" comment="squid is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<program_name operator="pattern match">^.*squid</program_name>
		</inetlisteningservers_test>
		<inetlisteningservers_test id="rlt-5" comment="radiusd is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<local_port operator="equals">1812</local_port>
				<program_name operator="pattern match">.*/radiusd</program_name>
				<protocol operator="equals">udp</protocol>
		</inetlisteningservers_test>
		<rpminfo_test id="rrt-201" comment="Red Hat 9 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">redhat-release</name>
				<version datatype="int" operator="equals">9</version>
		</rpminfo_test>
		<rpminfo_test id="rrt-202" comment="kernel version = 2.4.20-6" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<epoch operator="equals">NULL</epoch>
				<name operator="equals">kernel</name>
				<release datatype="int" operator="equals">6</release>
				<version operator="equals">2.4.20</version>
		</rpminfo_test>
		<rpminfo_test id="rrt-206" comment="Red Hat Enterprise 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">redhat-release</name>
				<version operator="pattern match">^3.S</version>
		</rpminfo_test>
		<rpminfo_test id="rrt-216" comment="Red Hat Enterprise 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">redhat-release</name>
				<version operator="pattern match">^.*3.S</version>
		</rpminfo_test>
		<rpminfo_test id="rrt-217" comment="php rpm is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">php</name>
		</rpminfo_test>
		<uname_test id="rut-201" comment="ix86 architecture" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
			<machine_class operator="pattern match">^i.*86</machine_class>
		</uname_test>
		<uname_test id="rut-204" comment="kernel 2.4.20-6 or earlier is running" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
			<os_release operator="equals">2.4.20-6</os_release>
		</uname_test>
		<uname_test id="rut-207" comment="ix86 architecture" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
			<machine_class operator="equals">x86_64</machine_class>
		</uname_test>
		<rpmversioncompare_test id="rvt-2" comment="FreeRADIUS rpm older than 1.0.1-1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name datatype="binary" operator="equals">FreeRADIUS</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.0.1</tested_version>
				<tested_release operator="equals">1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-201" comment="balsa version is less than 2.0.6-2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">balsa</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.0.6</tested_version>
				<tested_release datatype="int" operator="equals">2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-202" comment="cups version is less than 1.1.17-13.3" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">cups</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.1.17</tested_version>
				<tested_release operator="equals">13.3</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-203" comment="ddskk version is less than 11.6.0-11.90" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ddskk</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">11.6.0</tested_version>
				<tested_release operator="equals">11.90</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-204" comment="ddskk-xemacs version is less than 11.6.0-11.90" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ddskk-xemacs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">11.6.0</tested_version>
				<tested_release operator="equals">11.90</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-205" comment="eog version is less than 2.2.0-2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">eog</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.2.0</tested_version>
				<tested_release datatype="int" operator="equals">2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.11</tested_version>
				<tested_release operator="equals">0.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-207" comment="ethereal version is less than 0.9.13-1.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.13</tested_version>
				<tested_release operator="equals">1.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-208" comment="ethereal-gnome version is less than 0.9.13-1.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal-gnome</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.13</tested_version>
				<tested_release operator="equals">1.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-209" comment="evolution version is less than 1.2.2-5" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">evolution</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.2.2</tested_version>
				<tested_release datatype="int" operator="equals">5</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gdm</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">2.4.1.3</tested_version>
				<tested_release operator="equals">5.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-211" comment="ghostscript version is less than 7.05-32.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ghostscript</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">7.05</tested_version>
				<tested_release operator="equals">32.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-212" comment="gnupg version is less than 1.2.1-4" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gnupg</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.2.1</tested_version>
				<tested_release datatype="int" operator="equals">4</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-213" comment="gtkhtml version is less than 1.1.9-0.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gtkhtml</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.1.9</tested_version>
				<tested_release operator="equals">0.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-214" comment="gtkhtml version is less than 1.1.9-0.9.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gtkhtml</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.1.9</tested_version>
				<tested_release operator="equals">0.9.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-215" comment="httpd version is less than 2.0.40-21.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">httpd</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.0.40</tested_version>
				<tested_release operator="equals">21.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-216" comment="httpd version is less than 2.0.40-21.5" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">httpd</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.0.40</tested_version>
				<tested_release operator="equals">21.5</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-217" comment="kdebase version is less than 3.1-15" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kdebase</name>
				<tested_epoch datatype="int" operator="equals">6</tested_epoch>
				<tested_version operator="equals">3.1</tested_version>
				<tested_release datatype="int" operator="equals">15</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-218" comment="krb5-server version is less than 1.2.7-14" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">krb5-server</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.2.7</tested_version>
				<tested_release datatype="int" operator="equals">14</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-219" comment="krb5-libs version is less than 1.2.7-14" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">krb5-libs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.2.7</tested_version>
				<tested_release datatype="int" operator="equals">14</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-220" comment="krb5-workstation version is less than 1.2.7-14" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">krb5-workstation</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.2.7</tested_version>
				<tested_release datatype="int" operator="equals">14</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-221" comment="kernel version is less than 2.4.20-13.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">13.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-222" comment="kernel version is less than 2.4.20-18.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">18.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-223" comment="kernel version is less than 2.4.20-19.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">19.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-224" comment="kdelibs version is less than 3.1-12" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kdelibs</name>
				<tested_epoch datatype="int" operator="equals">6</tested_epoch>
				<tested_version operator="equals">3.1</tested_version>
				<tested_release datatype="int" operator="equals">12</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-225" comment="lprng version is less than 3.8.19-3.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">lprng</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">3.8.19</tested_version>
				<tested_release operator="equals">3.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-226" comment="lv version is less than 4.49.4-9.9.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">lv</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">4.49.4</tested_version>
				<tested_release operator="equals">9.9.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-227" comment="mutt version is less than 1.4.1-1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mutt</name>
				<tested_epoch datatype="int" operator="equals">5</tested_epoch>
				<tested_version operator="equals">1.4.1</tested_version>
				<tested_release datatype="int" operator="equals">1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mysql-server</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">3.23.56</tested_version>
				<tested_release operator="equals">1.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-229" comment="nfs-utils version is less than 1.0.1-3.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">nfs-utils</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.0.1</tested_version>
				<tested_release operator="equals">3.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-230" comment="openssh-server version is less than 3.5p1-6.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssh-server</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">3.5p1</tested_version>
				<tested_release operator="equals">6.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-231" comment="openssh-server version is less than 3.5p1-11" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssh-server</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">3.5p1</tested_version>
				<tested_release datatype="int" operator="equals">11</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-232" comment="openssl version is less than 0.9.7a-5" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release datatype="int" operator="equals">5</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-233" comment="openssl-devel version is less than 0.9.7a-5" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl-devel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release datatype="int" operator="equals">5</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-234" comment="openssl-perl version is less than 0.9.7a-5" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl-perl</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release datatype="int" operator="equals">5</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-235" comment="openssl096 version is less than 0.9.6-17" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl096</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.6</tested_version>
				<tested_release datatype="int" operator="equals">17</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-236" comment="openssl096b version is less than 0.9.6b-6" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl096b</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.6b</tested_version>
				<tested_release datatype="int" operator="equals">6</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-237" comment="pam_smb version is less than 1.1.6-9.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">pam_smb</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.1.6</tested_version>
				<tested_release operator="equals">9.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-238" comment="perl-CGI version is less than 2.81-88.3" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">perl-CGI</name>
				<tested_epoch datatype="int" operator="equals">2</tested_epoch>
				<tested_version operator="equals">2.81</tested_version>
				<tested_release operator="equals">88.3</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-239" comment="php version is less than 4.2.2-17.2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">php</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">4.2.2</tested_version>
				<tested_release operator="equals">17.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-240" comment="pine version is less than 4.44-19.90.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">pine</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">4.44</tested_version>
				<tested_release operator="equals">19.90.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-241" comment="postfix version is less than 1.1.12-1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">postfix</name>
				<tested_epoch datatype="int" operator="equals">2</tested_epoch>
				<tested_version operator="equals">1.1.12</tested_version>
				<tested_release datatype="int" operator="equals">1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">samba</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.2.7a</tested_version>
				<tested_release operator="equals">7.9.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">samba</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.2.7a</tested_version>
				<tested_release operator="equals">8.9.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-244" comment="wl version is less than 2.10.1-1.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">wl</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.10.1</tested_version>
				<tested_release operator="equals">1.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-245" comment="wl-xemacs version is less than 2.10.1-1.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">wl-xemacs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.10.1</tested_version>
				<tested_release operator="equals">1.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-246" comment="sendmail version is less than 8.12.8-5.90" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">sendmail</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">8.12.8</tested_version>
				<tested_release operator="equals">5.90</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-247" comment="sendmail version is less than 8.12.8-9.90" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">sendmail</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">8.12.8</tested_version>
				<tested_release operator="equals">9.90</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-248" comment="sendmail version is less than 8.12.8-6.90" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">sendmail</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">8.12.8</tested_version>
				<tested_release operator="equals">6.90</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-249" comment="squirrelmail version is less than 1.2.11-1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">squirrelmail</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.2.11</tested_version>
				<tested_release datatype="int" operator="equals">1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-250" comment="unzip version is less than 5.50-33" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">unzip</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">5.50</tested_version>
				<tested_release datatype="int" operator="equals">33</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-251" comment="up2date version is less than 3.1.23.1-5" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">up2date</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">3.1.23.1</tested_version>
				<tested_release datatype="int" operator="equals">5</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-252" comment="vsftpd version is less than 1.1.3-8" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">vsftpd</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.1.3</tested_version>
				<tested_release datatype="int" operator="equals">8</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-253" comment="xinetd version is less than 2:2.3.11-1.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">xinetd</name>
				<tested_epoch operator="equals">2</tested_epoch>
				<tested_version operator="equals">2.3.11</tested_version>
				<tested_release operator="equals">1.9.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-254" comment="xpdf version is less than 2.0.1-11" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">xpdf</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">2.0.1</tested_version>
				<tested_release datatype="int" operator="equals">11</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-255" comment="ypserv version is less than 2.8-0.9E" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ypserv</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.8</tested_version>
				<tested_release operator="equals">0.9E</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-257" comment="pwlib version is less than 1.4.7-4.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">pwlib</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.4.7</tested_version>
				<tested_release operator="equals">4.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-258" comment="netpbm version is less than 9.24-10.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">netpbm</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">9.24</tested_version>
				<tested_release operator="equals">10.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-259" comment="netpbm-devel version is less than 9.24-10.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">netpbm-devel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">9.24</tested_version>
				<tested_release operator="equals">10.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-260" comment="netpbm-progs version is less than 9.24-10.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">netpbm-progs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">9.24</tested_version>
				<tested_release operator="equals">10.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">XFree86</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">4.3.0</tested_version>
				<tested_release operator="equals">2.90.55</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-262" comment="netpbm version is less than 9.24-11.30.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">netpbm</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">9.24</tested_version>
				<tested_release operator="equals">11.30.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-263" comment="netpbm-devel version is less than 9.24-11.30.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">netpbm-devel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">9.24</tested_version>
				<tested_release operator="equals">11.30.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-264" comment="netpbm-progs version is less than 9.24-11.30.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">netpbm-progs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">9.24</tested_version>
				<tested_release operator="equals">11.30.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-265" comment="mutt version is less than 1.4.1-3.3" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mutt</name>
				<tested_epoch datatype="int" operator="equals">5</tested_epoch>
				<tested_version operator="equals">1.4.1</tested_version>
				<tested_release operator="equals">3.3</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-266" comment="mailman version is less than 2.1.1-5" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mailman</name>
				<tested_epoch datatype="int" operator="equals">3</tested_epoch>
				<tested_version operator="equals">2.1.1</tested_version>
				<tested_release datatype="int" operator="equals">5</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-267" comment="gaim version is less than 0.75-0.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gaim</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">0.75</tested_version>
				<tested_release operator="equals">0.9.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-268" comment="slocate version is less than 2.7-2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">slocate</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.7</tested_version>
				<tested_release datatype="int" operator="equals">2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-269" comment="mc version is less than 4.6.0-7.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mc</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">4.6.0</tested_version>
				<tested_release operator="equals">7.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-270" comment="kdelibs version is less than 3.1-13" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kdelibs</name>
				<tested_epoch datatype="int" operator="equals">6</tested_epoch>
				<tested_version operator="equals">3.1</tested_version>
				<tested_release datatype="int" operator="equals">13</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-271" comment="kernel version is less than 2.4.21-9.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">9.0.1.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-272" comment="kernel-smp version is less than 2.4.21-9.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-smp</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">9.0.1.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-273" comment="kernel-hugemem version is less than 2.4.21-9.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-hugemem</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">9.0.1.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-274" comment="pwlib version is less than 1.4.7-7.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">pwlib</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.4.7</tested_version>
				<tested_release operator="equals">7.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-275" comment="samba version is less than 3.0.2-6.3E" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">samba</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">3.0.2</tested_version>
				<tested_release operator="equals">6.3E</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-276" comment="mod_python version is less than 3.0.1-4" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mod_python</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">3.0.1</tested_version>
				<tested_release datatype="int" operator="equals">4</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-277" comment="XFree86 version is less than 4.3.0-55.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">XFree86</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">4.3.0</tested_version>
				<tested_release operator="equals">55.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-278" comment="libxml2 version is less than 2.5.10-6" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libxml2</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.5.10</tested_version>
				<tested_release datatype="int" operator="equals">6</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-279" comment="libxml2-devel version is less than 2.5.10-6" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libxml2-devel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.5.10</tested_version>
				<tested_release datatype="int" operator="equals">6</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-280" comment="libxml2-python version is less than 2.5.10-6" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libxml2-python</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.5.10</tested_version>
				<tested_release datatype="int" operator="equals">6</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-281" comment="kernel version is less than 2.4.20-30.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">30.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-282" comment="kernel-smp version is less than 2.4.20-30.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-smp</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">30.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-283" comment="kernel-bigmem version is less than 2.4.20-30.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-bigmem</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">30.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-284" comment="mutt version is less than 1.4.1-3.4" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mutt</name>
				<tested_epoch datatype="int" operator="equals">5</tested_epoch>
				<tested_version operator="equals">1.4.1</tested_version>
				<tested_release operator="equals">3.4</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-285" comment="gdk-pixbuf version is less than 0.22.0-6.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gdk-pixbuf</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">0.22.0</tested_version>
				<tested_release operator="equals">6.0.3</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-286" comment="gdk-pixbuf-devel version is less than 0.22.0-6.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gdk-pixbuf-devel</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">0.22.0</tested_version>
				<tested_release operator="equals">6.0.3</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-287" comment="gdk-pixbuf-gnome version is less than 0.22.0-6.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gdk-pixbuf-gnome</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">0.22.0</tested_version>
				<tested_release operator="equals">6.0.3</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-288" comment="gdk-pixbuf version is less than 0.22.0-6.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gdk-pixbuf</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">0.22.0</tested_version>
				<tested_release operator="equals">6.1.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-289" comment="gdk-pixbuf-devel version is less than 0.22.0-6.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gdk-pixbuf-devel</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">0.22.0</tested_version>
				<tested_release operator="equals">6.1.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-290" comment="gdk-pixbuf-gnome version is less than 0.22.0-6.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">gdk-pixbuf-gnome</name>
				<tested_epoch datatype="int" operator="equals">1</tested_epoch>
				<tested_version operator="equals">0.22.0</tested_version>
				<tested_release operator="equals">6.1.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-291" comment="tcpdump version is less than 3.7.2-7.9.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">tcpdump</name>
				<tested_epoch datatype="int" operator="equals">14</tested_epoch>
				<tested_version operator="equals">3.7.2</tested_version>
				<tested_release operator="equals">7.9.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-292" comment="sysstat version is less than 4.0.7-4.rhl9.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">sysstat</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">4.0.7</tested_version>
				<tested_release operator="equals">4.rhl9.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-293" comment="tcpdump version is less than 3.7.2-7.E3.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">tcpdump</name>
				<tested_epoch datatype="int" operator="equals">14</tested_epoch>
				<tested_version operator="equals">3.7.2</tested_version>
				<tested_release operator="equals">7.E3.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-294" comment="cvs version is less than 1.11.2-13" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">cvs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.11.2</tested_version>
				<tested_release datatype="int" operator="equals">13</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-295" comment="ethereal version is less than 0.10.0a-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.10.0a</tested_version>
				<tested_release operator="equals">0.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-296" comment="ethereal-gnome version is less than 0.10.0a-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal=gnome</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.10.0a</tested_version>
				<tested_release operator="equals">0.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-297" comment="kdepim version is less than 3.1-6" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kdepim</name>
				<tested_epoch datatype="int" operator="equals">6</tested_epoch>
				<tested_version operator="equals">3.1</tested_version>
				<tested_release datatype="int" operator="equals">6</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-298" comment="kernel version is less than 2.4.20-28.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">28.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-299" comment="kernel-smp version is less than 2.4.20-28.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-smp</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">28.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-300" comment="kernel-bigmem version is less than 2.4.20-28.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-bigmem</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.20</tested_version>
				<tested_release operator="equals">28.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-301" comment="nfs-utils version is less than 1.0.6-7.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">nfs-utils</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.0.6</tested_version>
				<tested_release operator="equals">7.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-302" comment="sysstat version is less than 4.0.7-4.EL3.2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">sysstat</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">4.0.7</tested_version>
				<tested_release operator="equals">4.EL3.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-303" comment="httpd version is less than 2.0.40-21.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">httpd</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.0.40</tested_version>
				<tested_release operator="equals">21.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-304" comment="httpd version is less than 2.0.46-26.ent" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">httpd</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.0.46</tested_version>
				<tested_release operator="equals">26.ent</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-305" comment="kdepim version is less than 3.1.3-3.3" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kdepim</name>
				<tested_epoch datatype="int" operator="equals">6</tested_epoch>
				<tested_version operator="equals">3.1.3</tested_version>
				<tested_release operator="equals">3.3</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-306" comment="cvs version is less than 1.11.2-14" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">cvs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.11.2</tested_version>
				<tested_release datatype="int" operator="equals">14</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-307" comment="kernel version is less than 2.4.21-4.0.2.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">4.0.2.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-308" comment="kernel-smp version is less than 2.4.21-4.0.2.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-smp</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">4.0.2.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-309" comment="kernel-bigmem version is less than 2.4.21-4.0.2.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-bigmem</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">4.0.2.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-310" comment="kernel version is less than 2.4.21-9.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">9.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-311" comment="net-snmp version is less than 5.0.9-2.30E.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">net-snmp</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">5.0.9</tested_version>
				<tested_release operator="equals">2.30E.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-312" comment="openssl version is less than 0.9.7a-33.4" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release operator="equals">33.4</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-313" comment="openssl-devel version is less than 0.9.7a-33.4" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl-devel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release operator="equals">33.4</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-314" comment="openssl-perl version is less than 0.9.7a-33.4" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl-perl</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release operator="equals">33.4</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-315" comment="openssl096b version is less than 0.9.6b-16" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl096b</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.6b</tested_version>
				<tested_release datatype="int" operator="equals">16</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-316" comment="mozilla-nss version is less than 1.4.2-0.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mozilla-nss</name>
				<tested_epoch datatype="int" operator="equals">37</tested_epoch>
				<tested_version operator="equals">1.4.2</tested_version>
				<tested_release operator="equals">0.9.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-317" comment="mozilla version is less than 1.4.2-0.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mozilla</name>
				<tested_epoch datatype="int" operator="equals">37</tested_epoch>
				<tested_version operator="equals">1.4.2</tested_version>
				<tested_release operator="equals">0.9.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-318" comment="openssl version is less than 0.9.7a-20" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release operator="equals">20.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-319" comment="openssl-devel version is less than 0.9.7a-20" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl-devel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release operator="equals">20.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-320" comment="openssl-perl version is less than 0.9.7a-20" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl-perl</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.7a</tested_version>
				<tested_release operator="equals">20.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-321" comment="openssl096 version is less than 0.9.6-25.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl096</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.6</tested_version>
				<tested_release operator="equals">25.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-322" comment="openssl096b version is less than 0.9.6b-15" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openssl096b</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.9.6b</tested_version>
				<tested_release datatype="int" operator="equals">15</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-323" comment="mod_ssl version is less than 2.0.46-32.ent" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mod_ssl</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.0.46</tested_version>
				<tested_release datatype="int" operator="equals">32.ent</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-325" comment="squid version is less than 2.5STABLE1-3.9" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">squid</name>
				<tested_epoch datatype="int" operator="equals">7</tested_epoch>
				<tested_version operator="equals">2.5STABLE1</tested_version>
				<tested_release operator="equals">3.9</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-326" comment="ethereal version is less than 0.10.3-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.10.3</tested_version>
				<tested_release operator="equals">0.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-327" comment="ethereal-gnome version is less than 0.10.3-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal-gnome</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.10.3</tested_version>
				<tested_release operator="equals">0.90.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-328" comment="ethereal version is less than 0.10.3-0.30E.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.10.3</tested_version>
				<tested_release operator="equals">0.30E.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-329" comment="ethereal-gnome version is less than 0.10.3-0.30E.1" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal-gnome</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.10.3</tested_version>
				<tested_release operator="equals">0.30E.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-330" comment="mozilla-nss version is less than 1.4.2-3.0.2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">mozilla-nss</name>
				<tested_epoch datatype="int" operator="equals">37</tested_epoch>
				<tested_version operator="equals">1.4.2</tested_version>
				<tested_release operator="equals">3.0.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-334" comment="kernel version is less than 2.4.21-9.0.3.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">9.0.3.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-335" comment="kernel-smp version is less than 2.4.21-9.0.3.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-smp</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">9.0.3.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-336" comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-hugemem</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">9.0.3.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-337" comment="squid version is less than 2.5.STABLE3-5.3E" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">squid</name>
				<tested_epoch datatype="int" operator="equals">7</tested_epoch>
				<tested_version operator="equals">2.5.STABLE3</tested_version>
				<tested_release operator="equals">5.3E</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-338" comment="ipsec-tools version is less than 0.2.5-0.4" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ipsec-tools</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.2.5</tested_version>
				<tested_release operator="equals">0.4</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-339" comment="kdelibs version is less than 3.1.3-6.4" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kdelibs</name>
				<tested_epoch datatype="int" operator="equals">6</tested_epoch>
				<tested_version operator="equals">3.1.3</tested_version>
				<tested_release operator="equals">6.4</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-340" comment="rsync version is less than 2.5.7-4.3E" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">rsync</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.5.7</tested_version>
				<tested_release operator="equals">4.3E</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-341" comment="cvs version is less than 1.11.2-22" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">cvs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.11.2</tested_version>
				<tested_release datatype="int" operator="equals">22</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-342" comment="libpng version is less than 1.2.2-21" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libpng</name>
				<tested_epoch datatype="int" operator="equals">2</tested_epoch>
				<tested_version operator="equals">1.2.2</tested_version>
				<tested_release datatype="int" operator="equals">21</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-343" comment="libpng-devel version is less than 1.2.2-21" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libpng-devel</name>
				<tested_epoch datatype="int" operator="equals">2</tested_epoch>
				<tested_version operator="equals">1.2.2</tested_version>
				<tested_release datatype="int" operator="equals">21</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-344" comment="libpng10 version is less than 1.0.13-12" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libpng</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.0.13</tested_version>
				<tested_release datatype="int" operator="equals">12</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-345" comment="libpng10-devel version is less than 1.0.13-12" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libpng-devel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.0.13</tested_version>
				<tested_release datatype="int" operator="equals">12</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-346" comment="kernel version is less than 2.4.21-15.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">15.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-347" comment="kernel version is less than 2.4.21-15.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">kernel-unsupported</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">2.4.21</tested_version>
				<tested_release operator="equals">15.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-348" comment="cvs version is less than 1.11.2-18" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">cvs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.11.2</tested_version>
				<tested_release datatype="int" operator="equals">18</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-349" comment="openoffice version is less than 1.1.0-15.EL" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">openoffice</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.1.0</tested_version>
				<tested_release operator="equals">15.EL</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-353" comment="tcpdump version is less than 3.7.2-7.E3.2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">tcpdump</name>
				<tested_epoch datatype="int" operator="equals">14</tested_epoch>
				<tested_version operator="equals">3.7.2</tested_version>
				<tested_release operator="equals">7.E3.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-354" comment="lha version is less than 1.14i-10.2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">lha</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.14i</tested_version>
				<tested_release operator="equals">10.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-355" comment="utempter version is less than 0.5.5-1.3EL.0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">utempter</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.5.5</tested_version>
				<tested_release operator="equals">1.3EL.0</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-356" comment="squid version is less than 2.5.STABLE3-6.3E" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">squid</name>
				<tested_epoch datatype="int" operator="equals">7</tested_epoch>
				<tested_version operator="equals">2.5.STABLE3</tested_version>
				<tested_release operator="equals">6.3E</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-357" comment="ethereal version is less than 0.10.3-0.30E.2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.10.3</tested_version>
				<tested_release operator="equals">0.30E.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-358" comment="ethereal-gnome version is less than 0.10.3-0.30E.2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">ethereal-gnome</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">0.10.3</tested_version>
				<tested_release operator="equals">0.30E.2</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-361" comment="krb5-libs rpm version prior to 1.2.7-24 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">krb5-libs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.2.7</tested_version>
				<tested_release operator="equals">24</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">cvs</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.11.2</tested_version>
				<tested_release operator="equals">24</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-363" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">squirrelmail</name>
				<tested_epoch operator="equals">NULL</tested_epoch>
				<tested_version operator="equals">1.4.3</tested_version>
				<tested_release operator="equals">0.e3.1</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-364" comment="kernel rpm older than 2.4.21-15.0.2.EL Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name>kernel</name>
				<tested_epoch>0</tested_epoch>
				<tested_version>2.4.21</tested_version>
				<tested_release>15.0.2.EL</tested_release>
				<installed_version>earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-366" comment="kernel-hugemem rpm older than 2.4.21-15.0.2.EL Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name>kernel-hugemem</name>
				<tested_epoch>0</tested_epoch>
				<tested_version>2.4.21</tested_version>
				<tested_release>15.0.2.EL</tested_release>
				<installed_version>earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-367" comment="kernel-smp rpm older than 2.4.21-15.0.2.EL Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name>kernel-smp</name>
				<tested_epoch>0</tested_epoch>
				<tested_version>2.4.21</tested_version>
				<tested_release>15.0.2.EL</tested_release>
				<installed_version>earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-368" comment="libpng rpm older than 1.2.2-24, Epoch 2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libpng</name>
				<tested_epoch operator="equals">2</tested_epoch>
				<tested_version operator="equals">1.2.2</tested_version>
				<tested_release operator="equals">24</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-369" comment="libpng-devel rpm older than 1.2.2-24, Epoch 2" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libpng-devel</name>
				<tested_epoch operator="equals">2</tested_epoch>
				<tested_version operator="equals">1.2.2</tested_version>
				<tested_release operator="equals">24</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-370" comment="libpng10-devel rpm older than 1.0.13-14, Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libpng10-devel</name>
				<tested_epoch operator="equals">0</tested_epoch>
				<tested_version operator="equals">1.0.13</tested_version>
				<tested_release operator="equals">14</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<rpmversioncompare_test id="rvt-371" comment="libpng10 rpm older than 1.0.13-14, Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
				<name operator="equals">libpng10</name>
				<tested_epoch operator="equals">0</tested_epoch>
				<tested_version operator="equals">1.0.13</tested_version>
				<tested_release operator="equals">14</tested_release>
				<installed_version operator="equals">earlier</installed_version>
		</rpmversioncompare_test>
		<package_test id="sat-10" comment="Core Solaris (SUNWcsu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWcsu</pkginst>
		</package_test>
		<package_test id="sat-12" comment="X Window System platform software (SUNWxwplt) installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWxwplt</pkginst>
		</package_test>
		<package_test id="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWnisu</pkginst>
		</package_test>
		<package_test id="sat-14" comment="Sendmail - user (SUNWsndmu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWsndmu</pkginst>
		</package_test>
		<package_test id="sat-15" comment="Samba (SUNWsmbar) installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUWNsmbar</pkginst>
		</package_test>
		<package_test id="sat-2" comment="Sun Crypto Accelerator 4000 software installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst>SUNWkcl2r</pkginst>
		</package_test>
		<package_test id="sat-3" comment="Sendmail - root (SUNWsndmr) installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWsndmr</pkginst>
		</package_test>
		<package_test id="sat-5" comment="Apache (SUNWapchu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWapchu</pkginst>
		</package_test>
		<package_test id="sat-6" comment="Toolktalk installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWtltk</pkginst>
		</package_test>
		<package_test id="sat-7" comment="System and Network Administration Framework Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWadmfw</pkginst>
		</package_test>
		<package_test id="sat-8" comment="SunCluster Component SUNWscvw installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst operator="equals">SUNWscvw</pkginst>
		</package_test>
		<package_test id="sat-9" comment="CDE Desktop Applications (SUNWdtdst) installed                                                                                               " xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<pkginst>SUNWdtdst</pkginst>
		</package_test>
		<process_test id="sct-2" comment="ypbind running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*ypbind.*</command>
		</process_test>
		<process_test id="sct-201" comment="inetd running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*inetd.*</command>
				<user_id operator="equals">root</user_id>
		</process_test>
		<process_test id="sct-202" comment="dmispd running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*dmispd.*</command>
		</process_test>
		<process_test id="sct-203" comment="snmpdx running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*snmpdx.*</command>
		</process_test>
		<process_test id="sct-204" comment="rpc.yppasswdd running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*rpc\.yppasswdd.*</command>
		</process_test>
		<process_test id="sct-205" comment="mibiisa running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*mibiisa.*</command>
		</process_test>
		<process_test id="sct-206" comment="dtlogin running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*dtlogin.*</command>
		</process_test>
		<process_test id="sct-207" comment="Apache running (httpd)" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">.*httpd</command>
		</process_test>
		<process_test id="sct-208" comment="Sendmail running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">.*sendmail .*</command>
		</process_test>
		<process_test id="sct-209" comment="Kerberos Key Distribution Center (krb5kdc) running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">.*krb5kdc.*</command>
		</process_test>
		<process_test id="sct-210" comment="Apache running with SunPlex Manager config" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^/usr/apache/bin/httpd.*SUNWscvw/conf/httpd.conf.*</command>
		</process_test>
		<process_test id="sct-211" comment="in.named running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="equals">/usr/sbin/in.named</command>
		</process_test>
		<process_test id="sct-3" comment="smbd running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*smbd.*</command>
		</process_test>
		<process_test id="sct-4" comment="sshd running" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<command operator="pattern match">^.*sshd.*</command>
		</process_test>
		<permission_test id="set-204" comment="File kcms_configure executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/kcms_configure
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-205" comment="File kcms_configure executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/kcms_configure
				</path>
				<suid datatype="int" operator="equals">1</suid>
		</permission_test>
		<permission_test id="set-206" comment="File kcms_configure executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/kcms_configure
				</path>
				<sgid datatype="int" operator="equals">1</sgid>
		</permission_test>
		<permission_test id="set-207" comment="File rpc.cmsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/rpc.cmsd
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="set-208" comment="File rpc.cmsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/rpc.cmsd
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="set-209" comment="File rpc.cmsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/rpc.cmsd
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-210" comment="File xlock SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/xlock
				</path>
				<suid datatype="int" operator="equals">1</suid>
		</permission_test>
		<permission_test id="set-211" comment="File xlock SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/xlock
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-212" comment="File Xsun SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/Xsun
				</path>
				<sgid datatype="int" operator="equals">1</sgid>
		</permission_test>
		<permission_test id="set-213" comment="File Xsun SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/Xsun
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-214" comment="File rpc.ttdbserverd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/rpc.ttdbserverd
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="set-215" comment="File rpc.ttdbserverd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/rpc.ttdbserverd
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="set-216" comment="File rpc.ttdbserverd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/rpc.ttdbserverd
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-217" comment="File cachefsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/lib/fs/cachefs/cachefsd
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="set-218" comment="File cachefsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/lib/fs/cachefs/cachefsd
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="set-219" comment="File cachefsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/lib/fs/cachefs/cachefsd
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-220" comment="File whodo SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					^/usr/sbin/sparcv./whodo
				</path>
				<suid datatype="int" operator="equals">1</suid>
		</permission_test>
		<permission_test id="set-221" comment="File whodo SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					^/usr/sbin/sparcv./whodo
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-222" comment="File rpc.rwalld executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/lib/netsvc/rwall/rpc.rwalld
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="set-223" comment="File rpc.rwalld executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/lib/netsvc/rwall/rpc.rwalld
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="set-224" comment="File rpc.rwalld executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/lib/netsvc/rwall/rpc.rwalld
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-225" comment="File admintool SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					^.*/bin/admintool
				</path>
				<suid datatype="int" operator="equals">1</suid>
		</permission_test>
		<permission_test id="set-226" comment="File admintool SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					^.*/bin/admintool
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-230" comment="File dtspcd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/dtspcd
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="set-231" comment="File dtspcd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/dtspcd
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="set-232" comment="File dtspcd executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/dt/bin/dtspcd
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-233" comment="File lbxproxy SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/lbxproxy
				</path>
				<sgid datatype="int" operator="equals">1</sgid>
		</permission_test>
		<permission_test id="set-234" comment="File lbxproxy SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/lbxproxy
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-235" comment="File kcms_server executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/kcms_server
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="set-236" comment="File kcms_server executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/kcms_server
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="set-237" comment="File kcms_server executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/kcms_server
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<permission_test id="set-246" comment="File xfs executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/xfs
				</path>
				<uexec datatype="int" operator="equals">1</uexec>
		</permission_test>
		<permission_test id="set-247" comment="File xfs executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/xfs
				</path>
				<gexec datatype="int" operator="equals">1</gexec>
		</permission_test>
		<permission_test id="set-248" comment="File xfs executable" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					/usr/openwin/bin/xfs
				</path>
				<oexec datatype="int" operator="equals">1</oexec>
		</permission_test>
		<file_test id="sft-201" comment="File kcms_configure exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/openwin/bin/kcms_configure</component>
				</path>
		</file_test>
		<file_test id="sft-202" comment="File rpc.cmsd exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/dt/bin/rpc.cmsd</component>
				</path>
		</file_test>
		<file_test id="sft-203" comment="File dmispd exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/lib/dmi/dmispd</component>
				</path>
		</file_test>
		<file_test id="sft-204" comment="File xlock exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/openwin/bin/xlock</component>
				</path>
		</file_test>
		<file_test id="sft-205" comment="File snmpdx exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/lib/snmp/snmpdx</component>
				</path>
		</file_test>
		<file_test id="sft-206" comment="File Xsun exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/openwin/bin/Xsun</component>
				</path>
		</file_test>
		<file_test id="sft-207" comment="File rpc.ttdbserverd exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
				</path>
		</file_test>
		<file_test id="sft-208" comment="File cachefsd exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
				</path>
		</file_test>
		<file_test id="sft-209" comment="File whodo exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component" operator="pattern match">
					<component type="literal">^/usr/sbin/sparcv./whodo$</component>
				</path>
		</file_test>
		<file_test id="sft-210" comment="File rpc.rwalld exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
				</path>
		</file_test>
		<file_test id="sft-211" comment="File admintool exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component" operator="pattern match">
					<component type="literal">^.*/bin/admintool$</component>
				</path>
		</file_test>
		<file_test id="sft-212" comment="File rpc.yppasswdd exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/lib/netsvc/rpc.yppasswdd</component>
				</path>
		</file_test>
		<file_test id="sft-213" comment="File mibiisa exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/lib/snmp/mibiisa</component>
				</path>
		</file_test>
		<file_test id="sft-214" comment="File dtspcd exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/dt/bin/dtspcd</component>
				</path>
		</file_test>
		<file_test id="sft-215" comment="File lbxproxy exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/openwin/bin/lbxproxy</component>
				</path>
		</file_test>
		<file_test id="sft-216" comment="File kcms_server exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/openwin/bin/kcms_server</component>
				</path>
		</file_test>
		<file_test id="sft-217" comment="File fs.auto exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/openwin/lib/fs.auto</component>
				</path>
		</file_test>
		<file_test id="sft-218" comment="File xfs exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/openwin/bin/xfs</component>
				</path>
		</file_test>
		<file_test id="sft-219" comment="File /usr/dt/bin/dtlogin exists" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/usr/dt/bin/dtlogin</component>
				</path>
		</file_test>
		<file_test id="sft-222" comment="Kerberos 5 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component">
					<component type="literal">/etc/krb5/krb5.conf</component>
				</path>
		</file_test>
		<file_test id="sft-3" comment="Lance Ethernet (le) interface configured to start" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<path datatype="component" operator="pattern match">
					<component type="literal">hostname6?\.le.*</component>
				</path>
		</file_test>
		<inetd_test id="sit-2" comment="inetd.conf contains smbd" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="pattern match">^.*smbd.*</server_program>
		</inetd_test>
		<inetd_test id="sit-201" comment="inetd.conf contains rpc.cmsd" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/dt/bin/rpc.cmsd</server_program>
		</inetd_test>
		<inetd_test id="sit-202" comment="inetd.conf contains rpc.ttdbserverd" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/dt/bin/rpc.ttdbserverd</server_program>
		</inetd_test>
		<inetd_test id="sit-203" comment="inetd.conf contains cachefsd" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/lib/fs/cachefs/cachefsd</server_program>
		</inetd_test>
		<inetd_test id="sit-204" comment="inetd.conf contains rpc.rwalld" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/lib/netsvc/rwall/rpc.rwalld</server_program>
		</inetd_test>
		<inetd_test id="sit-205" comment="inetd.conf contains dtspcd" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/dt/bin/dtspcd</server_program>
		</inetd_test>
		<inetd_test id="sit-206" comment="inetd.conf contains kcms_server" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/openwin/bin/kcms_server</server_program>
		</inetd_test>
		<inetd_test id="sit-207" comment="inetd.conf contains fs.auto" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/openwin/lib/fs.auto</server_program>
		</inetd_test>
		<inetd_test id="sit-209" comment="inetd.conf contains sadmind" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/sbin/sadmind</server_program>
		</inetd_test>
		<inetd_test id="sit-210" comment="Sadmin called using strong authentication" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<server_program operator="equals">/usr/sbin/sadmind</server_program>
				<server_arguments operator="equals">-S 2</server_arguments>
		</inetd_test>
		<patch_test id="spt-10" comment="Patch 106950-14 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">106950</base>
				<version datatype="int" operator="greater than or equal">14</version>
		</patch_test>
		<patch_test id="spt-11" comment="Patch 109147-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">109147</base>
				<version datatype="int" operator="greater than or equal">07</version>
		</patch_test>
		<patch_test id="spt-12" comment="Patch 112963-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112963</base>
				<version datatype="int" operator="greater than or equal">09</version>
		</patch_test>
		<patch_test id="spt-13" comment="Patch 107684-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">107684</base>
				<version datatype="int" operator="greater than or equal">10</version>
		</patch_test>
		<patch_test id="spt-14" comment="Patch 110615-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">110615</base>
				<version datatype="int" operator="greater than or equal">10</version>
		</patch_test>
		<patch_test id="spt-15" comment="Patch 114684-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">114684</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-16" comment="Patch 112604-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112604</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-17" comment="Patch 112609-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112609</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-18" comment="Patch 115172-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">115172</base>
				<version datatype="int" operator="greater than or equal">01</version>
		</patch_test>
		<patch_test id="spt-19" comment="Patch 113273-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">113273</base>
				<version datatype="int" operator="greater than or equal">04</version>
		</patch_test>
		<patch_test id="spt-2" comment="Patch 113575-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">113575</base>
				<version datatype="int" operator="greater than or equal">01</version>
		</patch_test>
		<patch_test id="spt-201" comment="Patch 108827-30 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108827</base>
				<version datatype="int" operator="greater than or equal">30</version>
		</patch_test>
		<patch_test id="spt-202" comment="Patch 108901-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108901</base>
				<version datatype="int" operator="greater than or equal">6</version>
		</patch_test>
		<patch_test id="spt-203" comment="Patch 108652-38 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108652</base>
				<version datatype="int" operator="greater than or equal">38</version>
		</patch_test>
		<patch_test id="spt-204" comment="Patch 108869-16 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108869</base>
				<version datatype="int" operator="greater than or equal">16</version>
		</patch_test>
		<patch_test id="spt-205" comment="Patch 108652-52 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108652</base>
				<version datatype="int" operator="greater than or equal">52</version>
		</patch_test>
		<patch_test id="spt-206" comment="Patch 110286-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">110286</base>
				<version datatype="int" operator="greater than or equal">9</version>
		</patch_test>
		<patch_test id="spt-207" comment="Patch 110896-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">110896</base>
				<version datatype="int" operator="greater than or equal">2</version>
		</patch_test>
		<patch_test id="spt-208" comment="Patch 108376-38 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108376</base>
				<version datatype="int" operator="greater than or equal">38</version>
		</patch_test>
		<patch_test id="spt-209" comment="Patch 111600-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">111600</base>
				<version datatype="int" operator="greater than or equal">1</version>
		</patch_test>
		<patch_test id="spt-210" comment="Patch 112899-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112899</base>
				<version datatype="int" operator="greater than or equal">1</version>
		</patch_test>
		<patch_test id="spt-211" comment="Patch 106942-22 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">106942</base>
				<version datatype="int" operator="greater than or equal">22</version>
		</patch_test>
		<patch_test id="spt-212" comment="Patch 108541-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108541</base>
				<version datatype="int" operator="greater than or equal">6</version>
		</patch_test>
		<patch_test id="spt-213" comment="Patch 111826-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">111826</base>
				<version datatype="int" operator="greater than or equal">1</version>
		</patch_test>
		<patch_test id="spt-214" comment="Patch 111596-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">111596</base>
				<version datatype="int" operator="greater than or equal">2</version>
		</patch_test>
		<patch_test id="spt-215" comment="Patch 107709-19 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">107709</base>
				<version datatype="int" operator="greater than or equal">19</version>
		</patch_test>
		<patch_test id="spt-216" comment="Patch 107337-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">107337</base>
				<version datatype="int" operator="greater than or equal">2</version>
		</patch_test>
		<patch_test id="spt-217" comment="Patch 110453-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">110453</base>
				<version datatype="int" operator="greater than or equal">1</version>
		</patch_test>
		<patch_test id="spt-218" comment="Patch 108721-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108721</base>
				<version datatype="int" operator="greater than or equal">2</version>
		</patch_test>
		<patch_test id="spt-219" comment="Patch 108949-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108949</base>
				<version datatype="int" operator="greater than or equal">7</version>
		</patch_test>
		<patch_test id="spt-220" comment="Patch 106934-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">106934</base>
				<version datatype="int" operator="greater than or equal">4</version>
		</patch_test>
		<patch_test id="spt-221" comment="Patch 112846-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112846</base>
				<version datatype="int" operator="greater than or equal">1</version>
		</patch_test>
		<patch_test id="spt-222" comment="Patch 107893-19 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">107893</base>
				<version datatype="int" operator="greater than or equal">19</version>
		</patch_test>
		<patch_test id="spt-223" comment="Patch 108652-51 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108652</base>
				<version datatype="int" operator="greater than or equal">51</version>
		</patch_test>
		<patch_test id="spt-224" comment="Patch 111590-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">111590</base>
				<version datatype="int" operator="greater than or equal">2</version>
		</patch_test>
		<patch_test id="spt-225" comment="Patch 108376-30 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108376</base>
				<version datatype="int" operator="greater than or equal">30</version>
		</patch_test>
		<patch_test id="spt-226" comment="Patch 109862-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">109862</base>
				<version datatype="int" operator="greater than or equal">3</version>
		</patch_test>
		<patch_test id="spt-227" comment="Patch 108117-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108117</base>
				<version datatype="int" operator="greater than or equal">6</version>
		</patch_test>
		<patch_test id="spt-228" comment="Patch 107893-20 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">107893</base>
				<version datatype="int" operator="greater than or equal">20</version>
		</patch_test>
		<patch_test id="spt-229" comment="Patch 107654-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">107654</base>
				<version datatype="int" operator="greater than or equal">10</version>
		</patch_test>
		<patch_test id="spt-230" comment="Patch 110286-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">110286</base>
				<version datatype="int" operator="greater than or equal">10</version>
		</patch_test>
		<patch_test id="spt-231" comment="Patch 108919-21 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="binary" operator="equals">108919</base>
				<version datatype="binary" operator="greater than or equal">21</version>
		</patch_test>
		<patch_test id="spt-232" comment="Patch 112807-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112807</base>
				<version datatype="int" operator="greater than or equal">09</version>
		</patch_test>
		<patch_test id="spt-233" comment="Patch 106541-33 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">106541</base>
				<version datatype="int" operator="greater than or equal">33</version>
		</patch_test>
		<patch_test id="spt-234" comment="Patch 109007-18 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="not equal">109007</base>
				<version datatype="int" operator="greater than or equal">18</version>
		</patch_test>
		<patch_test id="spt-235" comment="Patch 114332-12 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int">114332</base>
				<version datatype="int" operator="greater than or equal">12</version>
		</patch_test>
		<patch_test id="spt-236" comment="Patch 112908-12 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112908</base>
				<version datatype="int" operator="equals">12</version>
		</patch_test>
		<patch_test id="spt-238" comment="Patch 107684-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">107684</base>
				<version datatype="int" operator="greater than or equal">11</version>
		</patch_test>
		<patch_test id="spt-239" comment="Patch 110615-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">110615</base>
				<version datatype="int" operator="greater than or equal">11</version>
		</patch_test>
		<patch_test id="spt-240" comment="Patch 113575-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">113575</base>
				<version datatype="int" operator="greater than or equal">05</version>
		</patch_test>
		<patch_test id="spt-243" comment="Patch 114796-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">114796</base>
				<version datatype="int" operator="greater than or equal">04</version>
		</patch_test>
		<patch_test id="spt-244" comment="Patch 112237-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112237</base>
				<version datatype="int" operator="greater than or equal">11</version>
		</patch_test>
		<patch_test id="spt-245" comment="Patch 112390-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112390</base>
				<version datatype="int" operator="greater than or equal">09</version>
		</patch_test>
		<patch_test id="spt-246" comment="Patch 112908-16 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112908</base>
				<version datatype="int" operator="greater than or equal">16</version>
		</patch_test>
		<patch_test id="spt-247" comment="Patch 112536-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112536</base>
				<version datatype="int" operator="greater than or equal">05</version>
		</patch_test>
		<patch_test id="spt-248" comment="Patch 112908-13 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112908</base>
				<version datatype="int" operator="greater than or equal">13</version>
		</patch_test>
		<patch_test id="spt-249" comment="Patch 107180-31 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">107180</base>
				<version datatype="int" operator="greater than or equal">31</version>
		</patch_test>
		<patch_test id="spt-250" comment="Patch 112908-15 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112908</base>
				<version datatype="int" operator="greater than or equal">15</version>
		</patch_test>
		<patch_test id="spt-253" comment="Patch 116973-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">116973</base>
				<version datatype="int" operator="greater than or equal">01</version>
		</patch_test>
		<patch_test id="spt-254" comment="Patch 113146-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">113146</base>
				<version datatype="int" operator="greater than or equal">05</version>
		</patch_test>
		<patch_test id="spt-255" comment="Patch 112808-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112808</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-259" comment="Patch 116457-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">116457</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-260" comment="Patch 116442-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">116442</base>
				<version datatype="int" operator="greater than or equal">01</version>
		</patch_test>
		<patch_test id="spt-261" comment="Patch 116454-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">116454</base>
				<version operator="greater than or equal">01</version>
		</patch_test>
		<patch_test id="spt-263" comment="Patch 113146-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">113146</base>
				<version datatype="int" operator="greater than or equal">03</version>
		</patch_test>
		<patch_test id="spt-264" comment="Patch 109613-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">109613</base>
				<version datatype="int" operator="greater than or equal">07</version>
		</patch_test>
		<patch_test id="spt-265" comment="Patch 112810-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112810</base>
				<version datatype="int" operator="greater than or equal">06</version>
		</patch_test>
		<patch_test id="spt-266" comment="Patch 113505-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">113505</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-267" comment="Patch 113508-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">113508</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-268" comment="Patch 115054-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">115054</base>
				<version datatype="int" operator="greater than or equal">01</version>
		</patch_test>
		<patch_test id="spt-269" comment="Patch 115055-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">115055</base>
				<version datatype="int" operator="greater than or equal">01</version>
		</patch_test>
		<patch_test id="spt-270" comment="Patch 106938-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">106938</base>
				<version datatype="int" operator="greater than or equal">08</version>
		</patch_test>
		<patch_test id="spt-271" comment="Patch 109326-13 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">109326</base>
				<version datatype="int" operator="greater than or equal">13</version>
		</patch_test>
		<patch_test id="spt-272" comment="Patch 112970-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112970</base>
				<version datatype="int" operator="greater than or equal">06</version>
		</patch_test>
		<patch_test id="spt-4" comment="Patch 108376-25 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108376</base>
				<version datatype="int" operator="greater than or equal">25</version>
		</patch_test>
		<patch_test id="spt-5" comment="Patch 108652-30 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108652</base>
				<version datatype="int" operator="greater than or equal">30</version>
		</patch_test>
		<patch_test id="spt-6" comment="Patch 112300-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112300</base>
				<version datatype="int" operator="greater than or equal">01</version>
		</patch_test>
		<patch_test id="spt-7" comment="Patch 111085-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">112085</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-8" comment="Patch 108750-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">108750</base>
				<version datatype="int" operator="greater than or equal">02</version>
		</patch_test>
		<patch_test id="spt-9" comment="Patch 110322-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
				<base datatype="int" operator="equals">110322</base>
				<version datatype="int" operator="greater than or equal">01</version>
		</patch_test>
		<uname_test id="sut-202" comment="Solaris 8 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
			<os_name operator="equals">SunOS</os_name>
				<os_release operator="equals">5.8</os_release>
		</uname_test>
		<uname_test id="sut-203" comment="Solaris 7 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
			<os_name operator="equals">SunOS</os_name>
				<os_release operator="equals">5.7</os_release>
		</uname_test>
		<uname_test id="sut-204" comment="Solaris 9 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
			<os_name operator="equals">SunOS</os_name>
				<os_release operator="equals">5.9</os_release>
		</uname_test>
		<unknown_test id="ukn-10" comment="Word 97 is installed"/>
		<unknown_test id="ukn-11" comment="Word 98 is installed"/>
		<unknown_test id="ukn-12" comment="Excel 97 is installed"/>
		<unknown_test id="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)"/>
		<unknown_test id="ukn-16" comment="machine has followed the GDR update path and rpcrt4.dll is less than 5.2.3790.137"/>
		<unknown_test id="ukn-17" comment="machine has followed the QFE update path and rpcrt4.dll is less than 5.2.3790.141"/>
		<unknown_test id="ukn-18" comment="machine has followed the GDR update path and rpcss.dll is less than 5.2.3790.132"/>
		<unknown_test id="ukn-19" comment="machine has followed the QFE update path and rpcss.dll is less than 5.2.3790.142"/>
		<unknown_test id="ukn-2" comment="Lance Ethernet interface in use">
			<notes>
				<note author="none" date="2004-01-01"/>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-20" comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server"/>
		<unknown_test id="ukn-21" comment="this is a front-end server providing Outlook Web Access"/>
		<unknown_test id="ukn-22" comment="the back-end server is Exchange Server 2003 running on Windows 2003"/>
		<unknown_test id="ukn-24" comment="a website linked to the Crystal Reports Viewer is active"/>
		<unknown_test id="ukn-25" comment="Affected bkupexec.exe versions 3.60.1.298">
			<notes>
				<note author="none" date="2004-01-01">We think, but are not sure that the affected version of bkupexec.exe is 3.60.1.298 The file should be found in C:\Program Files\VERITAS\Backup Exec\NT\bkupexec.exe</note>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-26" comment="Basic Security Module enabled">
			<notes>
				<note author="none" date="2004-01-01">grep c2audit /etc/system True if "set c2audit:audit_load = 1" or similiar</note>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-27" comment="Auditing Administrative or System-Wide Administrative audit classes">
			<notes>
				<note author="none" date="2004-01-01">egrep ^flags:.*a[sd] /etc/security/audit_control True if any lines returned</note>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-29" comment="A service is using pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled">
			<notes>
				<note author="none" date="2004-01-01">egrep -e '[\t ]*[^#].*pam_krb5.*debug' /etc/pam.conf True if any lines returned</note>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-3" comment="configured to only offer streaming media over unicast"/>
		<unknown_test id="ukn-30" comment="Logging of LOG_DEBUG level messages is enabled">
			<notes>
				<note author="none" date="2004-01-01">egrep -e '*.debug|daemon.debug' /etc/syslog.conf True if any lines returned </note>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-33" comment="System is configured to use kerberos">
			<notes>
				<note author="none" date="2004-01-01">grep default_realm /etc/krb5/krb5.conf | grep -v __default_realm__ True if "default_realm = EXAMPLE.COM" where EXAMPLE.COM is a kerberos domain</note>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-36" comment="Sendmail has recipient or final rulesets">
			<notes>
				<note author="none" date="2004-01-01">egrep "^[Srecipient=2|S2]|^[^#]*\$&gt;2|^[^#]*\$&gt;recipient|^[^#]*\$&gt;4|^[^#]*\$&gt;final" /etc/mail/sendmail.cf True if any lines returned</note>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-37" comment="Solaris Kerberos explicit or rules-based mapping">
			<notes>
				<note author="none" date="2004-01-01">grep ^auth_to_local.* /etc/krb5/krb5.conf True if anything is returned</note>
			</notes>
		</unknown_test>
		<unknown_test id="ukn-38" comment="Service Pack 2 or less for Windows Office XP">
			<notes>
				<note author="none" date="2004-01-01">Service Pack 2 or less for Windows Office XP needs regex involving strings and less than</note>
			</notes>
		</unknown_test>
		<file_test id="wft-100" comment="the version of w3proxy.exe is less than 3.0.1200.257" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server\InstallationLocation</component>
					<component type="literal">\w3proxy.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>257</private>
				</version>
		</file_test>
		<file_test id="wft-101" comment="the version of wpsrv.exe is less than 3.0.1200.257" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server\InstallationLocation</component>
					<component type="literal">\wspsrv.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>257</private>
				</version>
		</file_test>
		<file_test id="wft-102" comment="the version of itircl.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\itircl.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3644</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-103" comment="the version of itss.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\itss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3644</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-106" comment="the version of msasn1.dll is less than 5.2.3790.88" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>88</private>
				</version>
		</file_test>
		<file_test id="wft-107" comment="the version of msasn1.dll is less than 5.1.2600.119" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>119</private>
				</version>
		</file_test>
		<file_test id="wft-108" comment="the version of msasn1.dll is less than 5.0.2195.6824" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6824</private>
				</version>
		</file_test>
		<file_test id="wft-109" comment="the version of msasn1.dll is less than 5.1.2600.1274" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1274</private>
				</version>
		</file_test>
		<file_test id="wft-110" comment="the version of wins.exe is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7255</private>
				</version>
		</file_test>
		<file_test id="wft-111" comment="the version of wins.exe is less than 4.0.1381.33554" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33554</private>
				</version>
		</file_test>
		<file_test id="wft-112" comment="the version of wins.exe is less than 5.2.3790.99" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>99</private>
				</version>
		</file_test>
		<file_test id="wft-113" comment="the version of fp30reg.dll is less than 10.00.4205.0000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\50\bin\fp30reg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>00</minor>
					<build>4205</build>
					<private>0000</private>
				</version>
		</file_test>
		<file_test id="wft-114" comment="the version of fp30reg.dll is less than 4.0.02.7523" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\40\bin\fp30reg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>00</minor>
					<build>02</build>
					<private>7523</private>
				</version>
		</file_test>
		<file_test id="wft-12" comment="the version of shtml.dll is less than 4.0.2.7523" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\40\isapi\shtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>00</minor>
					<build>02</build>
					<private>7523</private>
				</version>
		</file_test>
		<file_test id="wft-120" comment="the version of jscript.dll is less than 5.1.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\jscript.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>0</build>
					<private>8513</private>
				</version>
		</file_test>
		<file_test id="wft-121" comment="the version of jscript.dll is less than 5.5.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\jscript.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>0</build>
					<private>8513</private>
				</version>
		</file_test>
		<file_test id="wft-122" comment="the version of msgsvc.dll is less than 5.0.2195.6861" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6861</private>
				</version>
		</file_test>
		<file_test id="wft-123" comment="the version of wordpad.exe is less than 5.1.2600.1606" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">%windir%\Program Files\Windows NT\Accessories</component>
					<component type="literal">\wordpad.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1606</private>
				</version>
		</file_test>
		<file_test id="wft-130" comment="the version of outlook.exe is less than 10.00.5709.0000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE</component>
					<component type="literal">outlook.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>00</minor>
					<build>5709</build>
					<private>0000</private>
				</version>
		</file_test>
		<file_test id="wft-131" comment="the version of msgina.dll is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgina.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7255</private>
				</version>
		</file_test>
		<file_test id="wft-132" comment="the version of msgina.dll is less than 4.0.1381.33559" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgina.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33559</private>
				</version>
		</file_test>
		<file_test id="wft-133" comment="the version of msgina.dll is less than 5.1.2600.136" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msjet40.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6895</private>
				</version>
		</file_test>
		<file_test id="wft-134" comment="the version of msgina.dll is less than 5.1.2600.128" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgina.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>128</private>
				</version>
		</file_test>
		<file_test id="wft-135" comment="the version of msgina.dll is less than 5.1.2600.1343" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgina.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1343</private>
				</version>
		</file_test>
		<file_test id="wft-136" comment="the version of mf3216.dll is less than 4.0.1381.7263" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7263</private>
				</version>
		</file_test>
		<file_test id="wft-137" comment="the version of mf3216.dll is less than 4.0.1381.33562" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33562</private>
				</version>
		</file_test>
		<file_test id="wft-138" comment="the version of mf3216.dll is less than 5.0.2195.6898" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6898</private>
				</version>
		</file_test>
		<file_test id="wft-139" comment="the version of mf3216.dll is less than 5.1.2600.132" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>132</private>
				</version>
		</file_test>
		<file_test id="wft-14" comment="the version of excel.exe is less than 8.00.01.9904" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
					<component type="literal">\excel.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>00</minor>
					<build>01</build>
					<private>9904</private>
				</version>
		</file_test>
		<file_test id="wft-140" comment="the version of msdxm.ocx is less than 6.4.9.1124" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msdxm.ocx</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>4</minor>
					<build>9</build>
					<private>1124</private>
				</version>
		</file_test>
		<file_test id="wft-141" comment="the version of wmpcore.dll is less than 8.0.0.4482" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wmpcore.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>4482</private>
				</version>
		</file_test>
		<file_test id="wft-142" comment="the version of wmplayer.exe is less than 8.0.0.4482" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows Media Player\wmplayer.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>4482</private>
				</version>
		</file_test>
		<file_test id="wft-143" comment="the version of msdxm.ocx is less than 6.4.9.1121" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msdxm.ocx</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>4</minor>
					<build>9</build>
					<private>1121</private>
				</version>
		</file_test>
		<file_test id="wft-144" comment="the version of wmplayer.exe is less than 8.0.0.4490" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows Media Player\wmplayer.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>4490</private>
				</version>
		</file_test>
		<file_test id="wft-146" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7268" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7268</private>
				</version>
		</file_test>
		<file_test id="wft-147" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33591" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33591</private>
				</version>
		</file_test>
		<file_test id="wft-148" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6992</private>
				</version>
		</file_test>
		<file_test id="wft-149" comment="the version of mf3216.dll is less than 5.1.2600.1331" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mf3216.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1331</private>
				</version>
		</file_test>
		<file_test id="wft-15" comment="the version of excel.exe is less than 9.0.0.8216" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
					<component type="literal">\excel.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>8216</private>
				</version>
		</file_test>
		<file_test id="wft-150" comment="the version of h323.tsp is less than 5.0.2195.6901" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\h323.tsp</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6901</private>
				</version>
		</file_test>
		<file_test id="wft-151" comment="the version of h323.tsp is less than 5.2.3790.132" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\h323.tsp</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>132</private>
				</version>
		</file_test>
		<file_test id="wft-152" comment="the version of h323.tsp is less than 5.1.2600.1348" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\h323.tsp</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1348</private>
				</version>
		</file_test>
		<file_test id="wft-153" comment="the version of h323.tsp is less than 5.1.2600.134" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\h323.tsp</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>134</private>
				</version>
		</file_test>
		<file_test id="wft-154" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1605</private>
				</version>
		</file_test>
		<file_test id="wft-156" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Dhcpssvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7304</private>
				</version>
		</file_test>
		<file_test id="wft-157" comment="the version of lsasrv.dll is less than 5.2.3790.134" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>134</private>
				</version>
		</file_test>
		<file_test id="wft-158" comment="the version of lsasrv.dll is less than 5.1.2600.134" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>134</private>
				</version>
		</file_test>
		<file_test id="wft-159" comment="the version of lsasrv.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1361</private>
				</version>
		</file_test>
		<file_test id="wft-16" comment="the version of excel.exe is less than 10.0.5815.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
					<component type="literal">\excel.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>5815</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>220</private>
				</version>
		</file_test>
		<file_test id="wft-162" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Dhcpssvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33587</private>
				</version>
		</file_test>
		<file_test id="wft-163" comment="the version of wins.exe is less than 5.0.2195.7005" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7005</private>
				</version>
		</file_test>
		<file_test id="wft-164" comment="the version of wins.exe is less than 4.0.1381.7329" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7329</private>
				</version>
		</file_test>
		<file_test id="wft-165" comment="the version of wins.exe is less than 4.0.1381.33618" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33618</private>
				</version>
		</file_test>
		<file_test id="wft-17" comment="the version of winword.exe is less than 8.0.0.9315" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">\winword.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>9315</private>
				</version>
		</file_test>
		<file_test id="wft-170" comment="the version of schannel.dll is less than 4.87.1964.1880" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>87</minor>
					<build>1964</build>
					<private>1880</private>
				</version>
		</file_test>
		<file_test id="wft-171" comment="the version of schannel.dll is less than 5.1.2195.6899" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2195</build>
					<private>6899</private>
				</version>
		</file_test>
		<file_test id="wft-172" comment="the version of schannel.dll is less than 5.2.3790.132" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>132</private>
				</version>
		</file_test>
		<file_test id="wft-173" comment="the version of schannel.dll is less than 5.1.2600.136" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>136</private>
				</version>
		</file_test>
		<file_test id="wft-174" comment="the version of schannel.dll is less than 5.1.2600.1347" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\schannel.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1347</private>
				</version>
		</file_test>
		<file_test id="wft-177" comment="the version of comsvcs.dll is less than 2000.2.3511.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\comsvcs.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>2</minor>
					<build>3511</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-178" comment="the version of comsvcs.dll is less than 2001.12.4414.53" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\comsvcs.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2001</major>
					<minor>12</minor>
					<build>4414</build>
					<private>53</private>
				</version>
		</file_test>
		<file_test id="wft-179" comment="the version of comsvcs.dll is less than 2001.12.4720.130" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\comsvcs.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2001</major>
					<minor>12</minor>
					<build>4720</build>
					<private>130</private>
				</version>
		</file_test>
		<file_test id="wft-18" comment="the version of winword.exe is less than 8.0.0.9716" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">\winword.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>8</major>
					<minor>0</minor>
					<build>0</build>
					<private>9716</private>
				</version>
		</file_test>
		<file_test id="wft-180" comment="the version of msjet40.dll is less than 4.0.8618.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msjet40.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>8618</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-181" comment="the version of wmsjet40.dll is less than 4.0.8618.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wmsjet40.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>8618</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-182" comment="the version of inetcomm.dll is less than 5.50.4939.300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4939</build>
					<private>300</private>
				</version>
		</file_test>
		<file_test id="wft-183" comment="the version of inetcomm.dll is less than 6.00.2739.300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>00</minor>
					<build>2739</build>
					<private>300</private>
				</version>
		</file_test>
		<file_test id="wft-184" comment="the version of inetcomm.dll is less than 6.00.3790.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>00</minor>
					<build>37909</build>
					<private>137</private>
				</version>
		</file_test>
		<file_test id="wft-185" comment="the version of inetcomm.dll is less than 6.00.2800.1409" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>00</minor>
					<build>2800</build>
					<private>1409</private>
				</version>
		</file_test>
		<file_test id="wft-186" comment="the version of rpcrt4.dll is less than 5.0.2195.6904" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6904</private>
				</version>
		</file_test>
		<file_test id="wft-187" comment="the version of rpcrt4.dll is less than 5.1.2600.135" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>135</private>
				</version>
		</file_test>
		<file_test id="wft-188" comment="the version of rpcrt4.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1361</private>
				</version>
		</file_test>
		<file_test id="wft-189" comment="the version of rpcss.dll is less than 5.0.2195.6906" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6906</private>
				</version>
		</file_test>
		<file_test id="wft-19" comment="the version of winword.exe is less than 9.0.0.8216" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">\winword.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>8216</private>
				</version>
		</file_test>
		<file_test id="wft-190" comment="the version of wintrust.dll is less than 5.131.1880.14" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wintrust.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>1880</build>
					<private>14</private>
				</version>
		</file_test>
		<file_test id="wft-191" comment="the version of wintrust.dll is less than 5.131.2195.6824" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wintrust.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2195</build>
					<private>6824</private>
				</version>
		</file_test>
		<file_test id="wft-192" comment="the version of lsasrv.dll is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6902</private>
				</version>
		</file_test>
		<file_test id="wft-193" comment="the version of msasn1.dll is less than 5.0.2195.6905" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6905</private>
				</version>
		</file_test>
		<file_test id="wft-194" comment="the version of msasn1.dll is less than 5.2.3790.139" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>139</private>
				</version>
		</file_test>
		<file_test id="wft-195" comment="the version of msasn1.dll is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>137</private>
				</version>
		</file_test>
		<file_test id="wft-196" comment="the version of msasn1.dll is less than 5.1.2600.1362" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1362</private>
				</version>
		</file_test>
		<file_test id="wft-197" comment="the version of rpcss.dll is less than 5.1.2600.135" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>135</private>
				</version>
		</file_test>
		<file_test id="wft-198" comment="the version of rpcss.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1361</private>
				</version>
		</file_test>
		<file_test id="wft-199" comment="the version of rpcss.dll is less than 5.2.3790.146" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>142</private>
				</version>
		</file_test>
		<file_test id="wft-2" comment="the version of helpctr.exe is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>137</private>
				</version>
		</file_test>
		<file_test id="wft-20" comment="the version of wkssvc.dll is less than 5.1.2600.120" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wkssvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>120</private>
				</version>
		</file_test>
		<file_test id="wft-200" comment="the version of hypertrm.dll is less than 5.0.2195.7000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">%WinDir%\system32\</component>
					<component type="literal">hypertrm.dll </component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>7000</private>
				</version>
		</file_test>
		<file_test id="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4913</build>
					<private>1100</private>
				</version>
		</file_test>
		<file_test id="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>775</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2713</build>
					<private>1100</private>
				</version>
		</file_test>
		<file_test id="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2716</build>
					<private>2200</private>
				</version>
		</file_test>
		<file_test id="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5269</private>
				</version>
		</file_test>
		<file_test id="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4725</build>
					<private>2100</private>
				</version>
		</file_test>
		<file_test id="wft-207" comment="the version of netman.dll is less than 5.0.2195.5974" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netman.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5974</private>
				</version>
		</file_test>
		<file_test id="wft-208" comment="the version of mshtml.dll is less than 5.0.3504.2500" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3504</build>
					<private>2500</private>
				</version>
		</file_test>
		<file_test id="wft-209" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ism.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5671</private>
				</version>
		</file_test>
		<file_test id="wft-21" comment="the version of wkssvc.dll is less than 5.1.2600.1301" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wkssvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1301</private>
				</version>
		</file_test>
		<file_test id="wft-210" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\smtpsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>4905</private>
				</version>
		</file_test>
		<file_test id="wft-211" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ism.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>764</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-212" comment="the version of srvsvc.dll is less than 5.00.2195.4980" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\srvsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>4980</private>
				</version>
		</file_test>
		<file_test id="wft-213" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>2103</private>
				</version>
		</file_test>
		<file_test id="wft-214" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3513</build>
					<private>900</private>
				</version>
		</file_test>
		<file_test id="wft-215" comment="the version of mshtml.dll is less than 5.0.3502.4856" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3502</build>
					<private>4856</private>
				</version>
		</file_test>
		<file_test id="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2723</build>
					<private>2500</private>
				</version>
		</file_test>
		<file_test id="wft-217" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6106</private>
				</version>
		</file_test>
		<file_test id="wft-218" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rasman.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7140</private>
				</version>
		</file_test>
		<file_test id="wft-219" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rasman.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>4983</private>
				</version>
		</file_test>
		<file_test id="wft-22" comment="the version of winword.exe is less than 10.0.5815.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">\winword.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>5815</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-220" comment="File %windir%\system32\netlogon.dll version is less than 5.00.0893.1105" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netlogon.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>893</build>
					<private>1105</private>
				</version>
		</file_test>
		<file_test id="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\asp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6672</private>
				</version>
		</file_test>
		<file_test id="wft-222" comment="File sqlservr.exe version3 is less than 296" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>296</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-223" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\smss.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5695</private>
				</version>
		</file_test>
		<file_test id="wft-224" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ism.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3407</private>
				</version>
		</file_test>
		<file_test id="wft-225" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">ssmsrp70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>213</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-227" comment="File sqlservr.exe version3 less than 428" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>428</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\snmp.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7134</private>
				</version>
		</file_test>
		<file_test id="wft-229" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\mup.sys</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5080</private>
				</version>
		</file_test>
		<file_test id="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3523</build>
					<private>1700</private>
				</version>
		</file_test>
		<file_test id="wft-230" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>0</major>
					<minor>9</minor>
					<build>3940</build>
					<private>20</private>
				</version>
		</file_test>
		<file_test id="wft-231" comment="the version of mshtml.dll is less than 6.0.2715.400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2715</build>
					<private>400</private>
				</version>
		</file_test>
		<file_test id="wft-232" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2719</build>
					<private>2200</private>
				</version>
		</file_test>
		<file_test id="wft-233" comment="the version of locator.exe is less than 4.0.1381.7202" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Locator.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7202</private>
				</version>
		</file_test>
		<file_test id="wft-234" comment="the version of ntdll.dll is less than 5.0.2195.6685" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ntdll.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6685</private>
				</version>
		</file_test>
		<file_test id="wft-235" comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Drivers\SRV.SYS</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6699</private>
				</version>
		</file_test>
		<file_test id="wft-236" comment="the version of sqlservr.exe is less than 2000.80.608.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>608</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">odsole70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1264</private>
				</version>
		</file_test>
		<file_test id="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6802</private>
				</version>
		</file_test>
		<file_test id="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3810</build>
					<private>1700</private>
				</version>
		</file_test>
		<file_test id="wft-240" comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shdocvw.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3214</build>
					<private>2000</private>
				</version>
		</file_test>
		<file_test id="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2722</build>
					<private>900</private>
				</version>
		</file_test>
		<file_test id="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\snmp.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>4919</private>
				</version>
		</file_test>
		<file_test id="wft-243" comment="the version of mup.sys is less than 4.0.1381.7125" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\mup.sys</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7125</private>
				</version>
		</file_test>
		<file_test id="wft-244" comment="the version of shell32.dll is less than 5.00.3502.4718" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3502</build>
					<private>4718</private>
				</version>
		</file_test>
		<file_test id="wft-245" comment="the version of smss.exe is less than 4.0.1381.7152" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\smss.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7152</private>
				</version>
		</file_test>
		<file_test id="wft-246" comment="the version of netlogon.dll is less than 4.0.1381.7092" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netlogon.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7092</private>
				</version>
		</file_test>
		<file_test id="wft-247" comment="the version of mshtml.dll is less than 5.50.4923.2500" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4923</build>
					<private>2500</private>
				</version>
		</file_test>
		<file_test id="wft-248" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ism.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>776</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-249" comment="the version of cryptui.dll is less than 5.131.2600.117" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptui.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2600</build>
					<private>117</private>
				</version>
		</file_test>
		<file_test id="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4934</build>
					<private>1600</private>
				</version>
		</file_test>
		<file_test id="wft-250" comment="the version of cryptui.dll is less than 5.131.2600.1243" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptui.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2600</build>
					<private>1243</private>
				</version>
		</file_test>
		<file_test id="wft-251" comment="the version of xactsrv.dll is less than 5.0.2195.5971" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\xactsrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5971</private>
				</version>
		</file_test>
		<file_test id="wft-252" comment="the version of xenroll.dll is less than 5.131.3659.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\xenroll.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>3659</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-253" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>2784</private>
				</version>
		</file_test>
		<file_test id="wft-254" comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\idq.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3645</private>
				</version>
		</file_test>
		<file_test id="wft-255" comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptui.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2195</build>
					<private>6758</private>
				</version>
		</file_test>
		<file_test id="wft-256" comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\rdpwd.sys</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>5880</private>
				</version>
		</file_test>
		<file_test id="wft-257" comment="the version of jscript.dll is less than 5.6.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\jscript.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>6</minor>
					<build>0</build>
					<private>8513</private>
				</version>
		</file_test>
		<file_test id="wft-258" comment="the version of user32.dll is less than 5.1.2600.118" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>118</private>
				</version>
		</file_test>
		<file_test id="wft-259" comment="the version of user32.dll is less than 5.1.2600.1255" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1255</private>
				</version>
		</file_test>
		<file_test id="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2734</build>
					<private>1600</private>
				</version>
		</file_test>
		<file_test id="wft-260" comment="the version of wkssvc.dll is less than 5.0.2195.6861" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wkssvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6861</private>
				</version>
		</file_test>
		<file_test id="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\itircl.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>80</private>
				</version>
		</file_test>
		<file_test id="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4922</build>
					<private>900</private>
				</version>
		</file_test>
		<file_test id="wft-264" comment="the version of mswrd664.wpc is less than 2004.10.25.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\Microsoft Shared\TextConv\mswrd664.wpc</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>25</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-265" comment="the version of wmswrd632.wpc is less than 2004.10.25.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\Microsoft Shared\TextConv\wmswrd632.wpc</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>25</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-266" comment="the version of mshtml.dll is less than 6.00.3790.191" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>191</private>
				</version>
		</file_test>
		<file_test id="wft-267" comment="the version of mshtml.dll is less than 6.00.2800.1458" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1458</private>
				</version>
		</file_test>
		<file_test id="wft-268" comment="the version of mshtml.dll is less than 6.00.2743.600" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2743</build>
					<private>600</private>
				</version>
		</file_test>
		<file_test id="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4943</build>
					<private>400</private>
				</version>
		</file_test>
		<file_test id="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1276</private>
				</version>
		</file_test>
		<file_test id="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3532</build>
					<private>300</private>
				</version>
		</file_test>
		<file_test id="wft-271" comment="the version of tshoot.ocx is less than 1.0.1.2125" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tshoot.ocx</component>
				</path>
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>1</build>
					<private>2125</private>
				</version>
		</file_test>
		<file_test id="wft-272" comment="the version of msgsvc.dll is less than 5.1.2600.120" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>120</private>
				</version>
		</file_test>
		<file_test id="wft-273" comment="the version of msgsvc.dll is less than 5.1.2600.1301" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msgsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1301</private>
				</version>
		</file_test>
		<file_test id="wft-274" comment="File sqlservr.exe version3 is less than 578" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>578</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-275" comment="File xpstar.dll version3 is less than 561" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xpstar.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>561</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-276" comment="the version of srvsvc.dll is less than 5.0.2195.6110" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\srvsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-277" comment="the version of dxmasf.dll is less than 6.4.9.1121" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dxmasf.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>4</minor>
					<build>9</build>
					<private>1121</private>
				</version>
		</file_test>
		<file_test id="wft-278" comment="the version of sqlservr.exe is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>650</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-279" comment="the version of mshtml.dll is less than 5.00.3819.300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3819</build>
					<private>300</private>
				</version>
		</file_test>
		<file_test id="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>94</private>
				</version>
		</file_test>
		<file_test id="wft-280" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6753</private>
				</version>
		</file_test>
		<file_test id="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\Microsoft Shared\TextConv\mswrd632.wpc</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>25</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-282" comment="the version of kernel32.dll is less than 4.0.1381.7224" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\kernel32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7224</private>
				</version>
		</file_test>
		<file_test id="wft-283" comment="the version of nntpsvc.dll is less than 5.0.2195.3881" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nntpsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3881</private>
				</version>
		</file_test>
		<file_test id="wft-284" comment="machine has followed the GDR update path and rpcproxy.dll is less than 5.2.3790.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>137</private>
				</version>
				<development_class operator="not equal">srv03_qfe</development_class>
		</file_test>
		<file_test id="wft-285" comment="File %windir%\system32\user32.dll version is less than 5.00.2195.6799" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6799</private>
				</version>
		</file_test>
		<file_test id="wft-286" comment="the version of hhctrl.ocx is less than 5.2.3669.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hhctrl.ocx</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3669</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-287" comment="the version of hhsetup.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\hhsetup.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3644</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-288" comment="machine has followed the QFE update path and rpcproxy.dll is less than 5.2.3790.141" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>141</private>
				</version>
				<development_class>srv03_qfe</development_class>
		</file_test>
		<file_test id="wft-289" comment="the version of rpcproxy.dll is less than 5.0.2195.6904" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6904</private>
				</version>
		</file_test>
		<file_test id="wft-290" comment="the version of tlntsvr.exe is less than 5.0.33668.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tlntsvr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>33668</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-291" comment="the version of sp3res.dll is less than 5.0.2195.6713" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sp3res.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6713</private>
				</version>
		</file_test>
		<file_test id="wft-292" comment="the version of umandlg.dll is less than 1.0.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\umandlg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>0</build>
					<private>3</private>
				</version>
		</file_test>
		<file_test id="wft-293" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3510</build>
					<private>1100</private>
				</version>
		</file_test>
		<file_test id="wft-294" comment="the version of helpctr.exe is less than 5.2.3790.161" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>161</private>
				</version>
		</file_test>
		<file_test id="wft-295" comment="the version of ole32.dll is less than 4.0.1381.7263" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ole32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7263</private>
				</version>
		</file_test>
		<file_test id="wft-296" comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\ssinc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6624</private>
				</version>
		</file_test>
		<file_test id="wft-297" comment="the version of ole32.dll is less than 4.0.1381.33562" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\ole32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33562</private>
				</version>
		</file_test>
		<file_test id="wft-298" comment="the version of rpcproxy.dll is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7255</private>
				</version>
		</file_test>
		<file_test id="wft-299" comment="the version of rpcproxy.dll is less than 4.0.1381.33559" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcproxy.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33559</private>
				</version>
		</file_test>
		<file_test id="wft-3" comment="the version of helpctr.exe is less than 5.1.2600.1515" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1515</private>
				</version>
		</file_test>
		<file_test id="wft-30" comment="the version of msgsc.dll is less than 6.1.0.211" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\MSN Messenger\msgsc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>1</minor>
					<build>0</build>
					<private>211</private>
				</version>
		</file_test>
		<file_test id="wft-300" comment="the version of mswrd6.wpc is less than 10.0.803.2" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\Microsoft Shared\TextConv\mswrd6.wpc</component>
				</path>
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>803</build>
					<private>2</private>
				</version>
		</file_test>
		<file_test id="wft-301" comment="the version of msjava.dll is less than 5.0.3810.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msjava.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3810</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-302" comment="the version of msjava.dll is less than 5.0.3809.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msjava.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3809</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-303" comment="the version of helpctr.exe is less than 5.2.3790.125" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>125</private>
				</version>
		</file_test>
		<file_test id="wft-304" comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>769</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-305" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Msw3prt.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>2195</build>
					<private>3649</private>
				</version>
		</file_test>
		<file_test id="wft-306" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>164</private>
				</version>
		</file_test>
		<file_test id="wft-307" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4613</build>
					<private>1700</private>
				</version>
		</file_test>
		<file_test id="wft-308" comment="the version of mshtml.dll is less than 6.0.2712.0300" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2712</build>
					<private>0300</private>
				</version>
		</file_test>
		<file_test id="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4926</build>
					<private>2500</private>
				</version>
		</file_test>
		<file_test id="wft-31" comment="the version of fp4areg.dll is less than 4.0.02.7523" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\40\bin\fp4areg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>00</minor>
					<build>02</build>
					<private>7523</private>
				</version>
		</file_test>
		<file_test id="wft-310" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2716</build>
					<private>2200</private>
				</version>
		</file_test>
		<file_test id="wft-311" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2713</build>
					<private>1100</private>
				</version>
		</file_test>
		<file_test id="wft-312" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4927</build>
					<private>2100</private>
				</version>
		</file_test>
		<file_test id="wft-313" comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\snmp.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>133</private>
				</version>
		</file_test>
		<file_test id="wft-314" comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>70</minor>
					<build>11</build>
					<private>40</private>
				</version>
		</file_test>
		<file_test id="wft-315" comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>746</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-316" comment="the version of helpctr.exe is less than 5.1.2600.128" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>128</private>
				</version>
		</file_test>
		<file_test id="wft-317" comment="the version of helpctr.exe is less than 5.1.2600.1340" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\helpctr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1340</private>
				</version>
		</file_test>
		<file_test id="wft-318" comment="the version of evtgprov.dll is less than 5.1.2600.136" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\evtgprov.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>136</private>
				</version>
		</file_test>
		<file_test id="wft-319" comment="the version of evtgprov.dll is less than 5.1.2600.1363" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\evtgprov.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1363</private>
				</version>
		</file_test>
		<file_test id="wft-32" comment="the version of fp5areg.dll is less than 10.00.4205.0000" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Microsoft Shared\web server extensions\50\bin\fp5areg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>00</minor>
					<build>4205</build>
					<private>0000</private>
				</version>
		</file_test>
		<file_test id="wft-320" comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9001.40" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9001</build>
					<private>40</private>
				</version>
		</file_test>
		<file_test id="wft-321" comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9041.40" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9041</build>
					<private>40</private>
				</version>
		</file_test>
		<file_test id="wft-322" comment="the version of umandlg.dll is less than 1.0.0.4" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\umandlg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>0</build>
					<private>4</private>
				</version>
		</file_test>
		<file_test id="wft-323" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4616</build>
					<private>200</private>
				</version>
		</file_test>
		<file_test id="wft-324" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4701</build>
					<private>2400</private>
				</version>
		</file_test>
		<file_test id="wft-325" comment="the version of mswd6_32.wpc is less than 2004.10.21.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows NT\Accessories\mswd6_32.wpc</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>21</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-326" comment="the version of mswrd632.wpc is less than 2004.10.21.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Windows NT\Accessories\mswrd632.wpc</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2004</major>
					<minor>10</minor>
					<build>21</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-327" comment="the version of lsasrv.dll is less than 5.1.2600.2525" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>2525</private>
				</version>
		</file_test>
		<file_test id="wft-328" comment="the version of lsasrv.dll is less than 5.0.2195.6987" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6987</private>
				</version>
		</file_test>
		<file_test id="wft-329" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>780</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-33" comment="the version of h32fltr.dll is less than 3.0.1200.291" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fpc\InstallDirectory</component>
					<component type="literal">h323fltr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>291</private>
				</version>
		</file_test>
		<file_test id="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\msw3prt.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>2195</build>
					<private>58075</private>
				</version>
		</file_test>
		<file_test id="wft-331" comment="File %windir%\System32\code.asp is less than 4.0.1381.279" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\code.asp</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>279</private>
				</version>
		</file_test>
		<file_test id="wft-332" comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>2195</build>
					<private>6672</private>
				</version>
		</file_test>
		<file_test id="wft-333" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\nsiislog.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3931</private>
				</version>
		</file_test>
		<file_test id="wft-334" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\nsiislog.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3932</private>
				</version>
		</file_test>
		<file_test id="wft-335" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\nsiislog.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3861</private>
				</version>
		</file_test>
		<file_test id="wft-336" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1125</private>
				</version>
		</file_test>
		<file_test id="wft-337" comment="File %windir%\system\vserver.vxd version is less than 4.10.2001" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system\vserver.vxd</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>10</minor>
					<build>2001</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-338" comment="File %windir%\System32\w3svc.dll is less than 4.2.764.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>764</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-339" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\msw3prt.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>3649</private>
				</version>
		</file_test>
		<file_test id="wft-34" comment="the version of exprox.dll is less than 6.5.6980.57" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
					<component type="literal">\bin\exprox.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>5</minor>
					<build>6980</build>
					<private>57</private>
				</version>
		</file_test>
		<file_test id="wft-340" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Msw3prt</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>2956</private>
				</version>
		</file_test>
		<file_test id="wft-341" comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
					<component type="literal">\Crystal Decisions\1.1\Managed\CrystalDecisions.Web.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>1</minor>
					<build>9800</build>
					<private>9</private>
				</version>
		</file_test>
		<file_test id="wft-342" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6902</private>
				</version>
		</file_test>
		<file_test id="wft-343" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7265" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7265</private>
				</version>
		</file_test>
		<file_test id="wft-344" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33563" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33563</private>
				</version>
		</file_test>
		<file_test id="wft-345" comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Ipnathlp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6902</private>
				</version>
		</file_test>
		<file_test id="wft-346" comment="The version of Ipnathlp.dll is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ipnathlp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>137</private>
				</version>
		</file_test>
		<file_test id="wft-347" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ipnathlp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1364</private>
				</version>
		</file_test>
		<file_test id="wft-348" comment="The version of ipnathlp.dll is less than 5.2.3790.142" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ipnathlp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>142</private>
				</version>
		</file_test>
		<file_test id="wft-349" comment="the version of lsasrv.dll is less than 5.1.2600.1597" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\lsasrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1597</private>
				</version>
		</file_test>
		<file_test id="wft-35" comment="the version of sqlsrv32.dll is less than 3.70.11.46" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>70</minor>
					<build>11</build>
					<private>46</private>
				</version>
		</file_test>
		<file_test id="wft-350" comment="the version of wins.exe is less than 5.2.3790.239" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>239</private>
				</version>
		</file_test>
		<file_test id="wft-36" comment="the version of sqlsrv32.dll is less than 2000.80.747.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>747</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-360" comment="the version of dplayx.dll is less than 5.1.2600.148" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>148</private>
				</version>
		</file_test>
		<file_test id="wft-361" comment="the version of dplayx.dll is less than 5.1.2600.1517" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1517</private>
				</version>
		</file_test>
		<file_test id="wft-362" comment="the version of dplayx.dll is less than 5.2.3677.144" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3677</build>
					<private>144</private>
				</version>
		</file_test>
		<file_test id="wft-363" comment="the version of dplayx.dll is less than 5.3.0.903" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>3</minor>
					<build>0</build>
					<private>903</private>
				</version>
		</file_test>
		<file_test id="wft-364" comment="the version of dplayx.dll is less than 5.2.3790.163 on 64-bit edition" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>163</private>
				</version>
		</file_test>
		<file_test id="wft-365" comment="the version of dplayx.dll is less than 5.2.3790.163" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>163</private>
				</version>
		</file_test>
		<file_test id="wft-37" comment="the version of sqlsrv32.dll is less than 2000.81.9002.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9002</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-38" comment="the version of sqlsrv32.dll is less than 2000.81.9042.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9042</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-39" comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sqlsrv32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>85</minor>
					<build>1025</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-40" comment="the version of odbcbcp.dll is less than 3.70.11.46" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>70</minor>
					<build>11</build>
					<private>46</private>
				</version>
		</file_test>
		<file_test id="wft-41" comment="the version of odbcbcp.dll is less than 2000.80.747.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>747</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-414" comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7064" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tcpcfg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7064</private>
				</version>
		</file_test>
		<file_test id="wft-415" comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7097" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\tcpcfg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7097</private>
				</version>
		</file_test>
		<file_test id="wft-416" comment="File %windir%\system32\winlogon.exe version is less than 4.0.1381.7058" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\winlogon.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7058</private>
				</version>
		</file_test>
		<file_test id="wft-417" comment="File %ExchangeInstallDir%\bin\mad.exe is less than 6.0.5770.21" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
					<component type="literal">\bin\mad.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>5</minor>
					<build>5700</build>
					<private>21</private>
				</version>
		</file_test>
		<file_test id="wft-418" comment="the version of sqlservr.exe is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>650</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-419" comment="the version of odsole70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">odsole70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-42" comment="the version of odbcbcp.dll is less than 2000.81.9002.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9002</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-420" comment="the version of xpstar.dll is less than 2000.80.628.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">xpstar.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>628</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-421" comment="File %windir%\system32\dplayx.dll version is less than 5.0.2195.6927" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6927</private>
				</version>
		</file_test>
		<file_test id="wft-422" comment="File %windir%\system32\dplayx.dll version is less than 5.0.2258.410" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2258</build>
					<private>410</private>
				</version>
		</file_test>
		<file_test id="wft-423" comment="File %windir%\system32\dplayx.dll version is less than 5.1.2600.891" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>891</private>
				</version>
		</file_test>
		<file_test id="wft-424" comment="File %windir%\system32\dplayx.dll version is less than 5.2.3677.144" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3677</build>
					<private>144</private>
				</version>
		</file_test>
		<file_test id="wft-425" comment="File %windir%\system32\dplayx.dll version is less than 5.3.0.903" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dplayx.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>3</minor>
					<build>0</build>
					<private>903</private>
				</version>
		</file_test>
		<file_test id="wft-426" comment="the version of sqlservr.exe is less than 2000.80.636.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>636</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-427" comment="the version of ssnetlib.dll is less than 2000.80.636.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">ssnetlib.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>636</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-428" comment="the version of xpqueue.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">xpqueue.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-429" comment="the version of xprepl.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">xprepl.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-43" comment="the version of odbcbcp.dll is less than 2000.81.9042.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>81</minor>
					<build>9042</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-430" comment="the version of xplog70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">xplog70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-431" comment="the version of xpweb70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\sqlservr.exe\Path</component>
					<component type="literal">xpweb70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-432" comment="the version of crypt32.dll is less than 5.131.2600.1123" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\crypt32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>131</minor>
					<build>2600</build>
					<private>1123</private>
				</version>
		</file_test>
		<file_test id="wft-433" comment="the version of cryptdlg.dll is less than 5.0.1558.6608" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptdlg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>1558</build>
					<private>6608</private>
				</version>
		</file_test>
		<file_test id="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cryptdlg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>1558</build>
					<private>6072</private>
				</version>
		</file_test>
		<file_test id="wft-435" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6159</private>
				</version>
		</file_test>
		<file_test id="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7203</private>
				</version>
		</file_test>
		<file_test id="wft-437" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33545" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33545</private>
				</version>
		</file_test>
		<file_test id="wft-439" comment="the version of Sp3res.dll is less than 5.0.2195.6928" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Sp3res.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6928</private>
				</version>
		</file_test>
		<file_test id="wft-44" comment="the version of odbcbcp.dll is less than 2000.85.1025.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\odbcbcp.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>85</minor>
					<build>1025</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-440" comment="the version of psxss.exe is less than 4.0.1381.33567" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\psxss.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33567</private>
				</version>
		</file_test>
		<file_test id="wft-441" comment="the version of psxss.exe is less than 5.0.2195.6929" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\psxss.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6929</private>
				</version>
		</file_test>
		<file_test id="wft-442" comment="the version of Umandlg.dll is less than 1.0.0.5" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Umandlg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>1</major>
					<minor>0</minor>
					<build>0</build>
					<private>5</private>
				</version>
		</file_test>
		<file_test id="wft-443" comment="the version of psxss.exe is less than 4.0.1381.7269" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\psxss.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7269</private>
				</version>
		</file_test>
		<file_test id="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\itss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>185</private>
				</version>
		</file_test>
		<file_test id="wft-445" comment="the version of mstask.dll is less than 4.71.2195.6920" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>71</minor>
					<build>2195</build>
					<private>6920</private>
				</version>
		</file_test>
		<file_test id="wft-446" comment="the version of w3svc.dll is less than 4.2.788.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\w3svc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>2</minor>
					<build>788</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-447" comment="the version of shell32.dll is less than 5.0.3900.6922" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3900</build>
					<private>6922</private>
				</version>
		</file_test>
		<file_test id="wft-448" comment="the version of shell32.dll is less than 6.0.3790.168" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>168</private>
				</version>
		</file_test>
		<file_test id="wft-449" comment="the version of shell32.dll is less than 6.0.2800.1517" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1517</private>
				</version>
		</file_test>
		<file_test id="wft-45" comment="the version of msgsc.dll is greater than 6.0.0.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\MSN Messenger\msgsc.dll</component>
				</path>
				<version datatype="version" operator="greater than">
					<major>6</major>
					<minor>0</minor>
					<build>0</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-450" comment="the version of shell32.dll is less than 6.0.2800.1556" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1556</private>
				</version>
		</file_test>
		<file_test id="wft-451" comment="the version of shell32.dll is less than 6.0.3790.163" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>163</private>
				</version>
		</file_test>
		<file_test id="wft-452" comment="the version of shell32.dll is less than 4.72.3841.1100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>72</minor>
					<build>3841</build>
					<private>1100</private>
				</version>
		</file_test>
		<file_test id="wft-453" comment="the version of mstask.dll is less than 5.1.2600.155" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>155</private>
				</version>
		</file_test>
		<file_test id="wft-454" comment="the version of mstask.dll is less than 5.1.2600.1564" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1564</private>
				</version>
		</file_test>
		<file_test id="wft-455" comment="the version of mstask.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1555</private>
				</version>
		</file_test>
		<file_test id="wft-457" comment="the version of mstask.dll is less than 4.71.1979.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mstask.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>71</minor>
					<build>1979</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-458" comment="the version of shell32.dll is less than 6.0.2800.1233 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1233</private>
				</version>
		</file_test>
		<file_test id="wft-459" comment="the version of shell32.dll is less than 6.0.2600.115 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2600</build>
					<private>115</private>
				</version>
		</file_test>
		<file_test id="wft-46" comment="the version of nscm.exe is less than 4.1.0.3934" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Windows Media\Server\nscm.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3934</private>
				</version>
		</file_test>
		<file_test id="wft-461" comment="the version of inetcomm.dll is less than 6.0.2742.200" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2742</build>
					<private>200</private>
				</version>
		</file_test>
		<file_test id="wft-462" comment="machine has followed the GDR update path and inetcomm.dll is less than 6.0.3790.181" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>181</private>
				</version>
		</file_test>
		<file_test id="wft-463" comment="the version of netbt.sys is less than 5.1.2600.117" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\netbt.sys</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>117</private>
				</version>
		</file_test>
		<file_test id="wft-464" comment="the version of netbt.sys is less than 5.1.2600.1243" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\drivers\netbt.sys</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1243</private>
				</version>
		</file_test>
		<file_test id="wft-465" comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.112" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Drivers\SRV.SYS</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>112</private>
				</version>
		</file_test>
		<file_test id="wft-466" comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.1193" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Drivers\SRV.SYS</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1193</private>
				</version>
		</file_test>
		<file_test id="wft-467" comment="the version of inetcomm.dll is less than 6.0.2800.1441" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1441</private>
				</version>
		</file_test>
		<file_test id="wft-468" comment="machine has followed the QFE update path and inetcomm.dll is less than 6.0.3790.185" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>185</private>
				</version>
		</file_test>
		<file_test id="wft-469" comment="the version of inetcomm.dll is less than 5.50.4942.400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetcomm.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4942</build>
					<private>400</private>
				</version>
		</file_test>
		<file_test id="wft-47" comment="the version of nspmon.exe is less than 4.1.0.3934" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Windows Media\Server\nspmon.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>1</minor>
					<build>0</build>
					<private>3934</private>
				</version>
		</file_test>
		<file_test id="wft-470" comment="the version of winword.exe is less than 9.0.0.7924" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">\winword.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>7924</private>
				</version>
		</file_test>
		<file_test id="wft-471" comment="the version of shell32.dll is less than 4.0.1381.7267" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7267</private>
				</version>
		</file_test>
		<file_test id="wft-474" comment="the version of user32.dll is less than 4.0.1381.7177" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\user32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7177</private>
				</version>
		</file_test>
		<file_test id="wft-475" comment="the version of gdi32.dll is less than 4.0.1381.7177" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\gdi32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7177</private>
				</version>
		</file_test>
		<file_test id="wft-476" comment="the version of winsrv.dll is less than 4.0.1381.7202" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\winsrv.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7202</private>
				</version>
		</file_test>
		<file_test id="wft-477" comment="the version of win32k.sys is less than 4.0.1381.7207" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\win32k.sys</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7207</private>
				</version>
		</file_test>
		<file_test id="wft-478" comment="the version of winword.exe is less than 9.0.0.6926" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">\winword.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>6926</private>
				</version>
		</file_test>
		<file_test id="wft-481" comment="the version of msadco.dll is less than 2.62.9119.1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\System\msadc\msadco.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>62</minor>
					<build>9119</build>
					<private>1</private>
				</version>
		</file_test>
		<file_test id="wft-482" comment="the version of msadco.dll is less than 2.53.6202.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\System\msadc\msadco.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>53</minor>
					<build>6202</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-483" comment="the version of msadco.dll is less than 2.12.5118.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
					<component type="literal">\Common Files\System\msadc\msadco.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>12</minor>
					<build>5118</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-484" comment="the version of msohev.dll less than 10.0.2609.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office</component>
					<component type="literal">\10.0\Common\InstallRoot\msohev.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>2609</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-485" comment="the version of cdo.dll is less than 5.5.2558.10" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\cdo.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>2558</build>
					<private>10</private>
				</version>
		</file_test>
		<file_test id="wft-486" comment="the version of winword.exe is less than 9.0.0.6328" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
					<component type="literal">\winword.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>9</major>
					<minor>0</minor>
					<build>0</build>
					<private>6328</private>
				</version>
		</file_test>
		<file_test id="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6CE92CC2CB71D1\9040210900063D11C8EF10054038389C</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2003</major>
					<minor>1100</minor>
					<build>6252</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-49" comment="the version of msasn1.dll is less than 5.0.2195.6823" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\msasn1.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6823</private>
				</version>
		</file_test>
		<file_test id="wft-490" comment="the version of shell32.dll is less than 4.0.1381.7116" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7116</private>
				</version>
		</file_test>
		<file_test id="wft-491" comment="the version of sqlisapi.dll is less than 2000.80.309.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\</component>
					<component type="literal">\System\Ole DB folder\sqlisapi.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>309</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-492" comment="the version of sqlservr.exe is less than 2000.80.760.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>760</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-493" comment="the version of sxs.dll is less than 5.2.3790.121" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sxs.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>121</private>
				</version>
		</file_test>
		<file_test id="wft-494" comment="the version of sxs.dll is less than 5.1.2600.1363" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\sxs.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1363</private>
				</version>
		</file_test>
		<file_test id="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A0A0D0E3C44B1C\9040210900063D11C8EF10054038389C</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3264</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5052E3053B8D3D</component>
				</path>
				<version datatype="version" operator="less than">
					<major>10</major>
					<minor>0</minor>
					<build>6714</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-499" comment="the version of shell32.dll is less than 5.0.3900.6970" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3900</build>
					<private>6970</private>
				</version>
		</file_test>
		<file_test id="wft-50" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dbmslpcn.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-501" comment="the version of httpext.dll is less than 5.0.2195.6958" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6958</private>
				</version>
		</file_test>
		<file_test id="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\smtpsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>211</private>
				</version>
		</file_test>
		<file_test id="wft-503" comment="the version of httpext.dll is less than 6.0.2600.165" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2600</build>
					<private>165</private>
				</version>
		</file_test>
		<file_test id="wft-504" comment="the version of httpext.dll is less than 6.0.2600.1579" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2600</build>
					<private>1579</private>
				</version>
		</file_test>
		<file_test id="wft-505" comment="the version of vdmdbg.dll is less than 5.0.2195.6946" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\vdmdbg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6946</private>
				</version>
		</file_test>
		<file_test id="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nntpsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>206</private>
				</version>
		</file_test>
		<file_test id="wft-507" comment="the version of gdi32.dll is less than 5.0.2195.6945" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\gdi32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6945</private>
				</version>
		</file_test>
		<file_test id="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\win32k.sys</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>198</private>
				</version>
		</file_test>
		<file_test id="wft-509" comment="the version of shell32.dll (WOW64) is less than 6.0.2800.1580" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>9</minor>
					<build>2800</build>
					<private>1580</private>
				</version>
		</file_test>
		<file_test id="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-510" comment="the version of shell32.dll is less than 6.0.2800.1580" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1580</private>
				</version>
		</file_test>
		<file_test id="wft-511" comment="the version of gdi32.dll is less than 4.0.1381.33566" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\gdi32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33566</private>
				</version>
		</file_test>
		<file_test id="wft-512" comment="the version of gdi32.dll is less than 4.0.1381.7270" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\gdi32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7270</private>
				</version>
		</file_test>
		<file_test id="wft-514" comment="the version of shell32.dll is less than 6.0.2750.166" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2750</build>
					<private>166</private>
				</version>
		</file_test>
		<file_test id="wft-515" comment="the version of httpext.dll is less than 6.0.3790.212" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\httpext.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>212</private>
				</version>
		</file_test>
		<file_test id="wft-516" comment="the version of shell32.dll is less than 4.72.3843.3100" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>72</minor>
					<build>3843</build>
					<private>3100</private>
				</version>
		</file_test>
		<file_test id="wft-517" comment="the version of shell32.dll is less than 4.0.1381.33564" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>3356</private>
				</version>
		</file_test>
		<file_test id="wft-518" comment="the version of nddenb32.dll is less than 4.0.1381.7268" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\nddenb32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7268</private>
				</version>
		</file_test>
		<file_test id="wft-519" comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6966</private>
				</version>
		</file_test>
		<file_test id="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">ssmslpcn.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-520" comment="the version of nddenb32.dll is less than 4.0.1381.33565" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\nddenb32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33565</private>
				</version>
		</file_test>
		<file_test id="wft-521" comment="the version of netdde.exe is less than 4.0.1381.33574" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33574</private>
				</version>
		</file_test>
		<file_test id="wft-522" comment="the version of netdde.exe is less than 4.0.1381.7280" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7280</private>
				</version>
		</file_test>
		<file_test id="wft-523" comment="the version of grpconv.exe (system32) is less than 4.0.1381.7286" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7286</private>
				</version>
		</file_test>
		<file_test id="wft-524" comment="the version of grpconv.exe (system32) is less than 4.0.1381.33577" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33577</private>
				</version>
		</file_test>
		<file_test id="wft-525" comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>205</private>
				</version>
		</file_test>
		<file_test id="wft-526" comment="the version of grpconv.exe (syswow64) is less than 5.2.3790.205" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\syswow64\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>205</private>
				</version>
		</file_test>
		<file_test id="wft-527" comment="the version of netdde.exe is less than 5.0.2195.6952" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6952</private>
				</version>
		</file_test>
		<file_test id="wft-528" comment="the version of nddenb32.dll is less than 5.0.2195.6922" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6922</private>
				</version>
		</file_test>
		<file_test id="wft-529" comment="the version of grpconv.exe is less than 5.1.2600.166" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>166</private>
				</version>
		</file_test>
		<file_test id="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">ssnetlib.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-530" comment="the version of grpconv.exe is less than 5.1.2600.1580" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\grpconv.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1580</private>
				</version>
		</file_test>
		<file_test id="wft-531" comment="the version of grpconv.exe (syswow64) is less than 5.1.2600.1580" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\syswow64\shell32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1580</private>
				</version>
		</file_test>
		<file_test id="wft-532" comment="the 32-bit version of zipfldr.dll is less than 6.0.2750.167" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\zipfldr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2750</build>
					<private>167</private>
				</version>
		</file_test>
		<file_test id="wft-533" comment="the version of nntpsvc.dll is less than 5.0.2195.6972" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nntpsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6972</private>
				</version>
		</file_test>
		<file_test id="wft-534" comment="the 32-bit version of zipfldr.dll is less than 6.0.2800.1584" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\zipfldr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1584</private>
				</version>
		</file_test>
		<file_test id="wft-535" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\vdmdbg.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1560</private>
				</version>
		</file_test>
		<file_test id="wft-536" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\zipfldr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1584</private>
				</version>
		</file_test>
		<file_test id="wft-537" comment="the 32-bit version of zipfldr.dll is less than 6.0.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\zipfldr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>198</private>
				</version>
		</file_test>
		<file_test id="wft-538" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\zipfldr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>198</private>
				</version>
		</file_test>
		<file_test id="wft-539" comment="the version of nntpsvc.dll is less than 5.5.1877.79" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nntpsvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>5</minor>
					<build>1877</build>
					<private>79</private>
				</version>
		</file_test>
		<file_test id="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">ssnmpn70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-540" comment="the version of nddenb32.dll is less than 5.2.3790.173" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nddenb32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>173</private>
				</version>
		</file_test>
		<file_test id="wft-541" comment="the version of netdde.exe is less than 5.2.3790.184" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>184</private>
				</version>
		</file_test>
		<file_test id="wft-542" comment="the 64-bit WOW version of nddenb32.dll is less than 5.2.3790.193" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\nddenb32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>193</private>
				</version>
		</file_test>
		<file_test id="wft-543" comment="the 64-bit WOW version of netdde.exe is less than 5.2.3790.193" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>2</minor>
					<build>3790</build>
					<private>193</private>
				</version>
		</file_test>
		<file_test id="wft-544" comment="the version of netdde.exe is less than 5.1.2600.1567" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1567</private>
				</version>
		</file_test>
		<file_test id="wft-545" comment="the version of nddenb32.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nddenb32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1555</private>
				</version>
		</file_test>
		<file_test id="wft-546" comment="the version of nddenb32.dll is less than 5.1.2600.149" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\nddenb32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>149</private>
				</version>
		</file_test>
		<file_test id="wft-547" comment="the version of netdde.exe is less than 5.1.2600.158" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\inetsrv\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>158</private>
				</version>
		</file_test>
		<file_test id="wft-548" comment="the 64-bit WOW version of netdde.exe is less than 5.1.2600.1567" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\netdde.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1567</private>
				</version>
		</file_test>
		<file_test id="wft-549" comment="the 64-bit WOW version of nddenb32.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\SysWOW64\nddenb32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>1555</private>
				</version>
		</file_test>
		<file_test id="wft-55" comment="the version of msgprox.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\SharedCode</component>
					<component type="literal">msgprox.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-550" comment="machine has followed the GDR update path and mshtml.dll is less than  6.0.2900.2523 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2900</build>
					<private>2523</private>
				</version>
		</file_test>
		<file_test id="wft-551" comment="machine has followed the QFE update path and mshtml.dll is less than  6.0.2900.2524 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2900</build>
					<private>2524</private>
				</version>
		</file_test>
		<file_test id="wft-552" comment="the version of rpcrt4.dll is less than 4.0.1381.7299" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7299</private>
				</version>
		</file_test>
		<file_test id="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>219</private>
				</version>
		</file_test>
		<file_test id="wft-559" comment="the version of rpcrt4.dll is less than 4.0.1381.33578" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcrt4.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>33578</private>
				</version>
		</file_test>
		<file_test id="wft-56" comment="the version of replrec.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\SharedCode</component>
					<component type="literal">replrec.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3821</build>
					<private>2800</private>
				</version>
		</file_test>
		<file_test id="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3534</build>
					<private>2800</private>
				</version>
		</file_test>
		<file_test id="wft-562" comment="the version of mshtml.dll is less than 5.5.4945.2800 " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>4945</build>
					<private>2800</private>
				</version>
		</file_test>
		<file_test id="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2745</build>
					<private>2800</private>
				</version>
		</file_test>
		<file_test id="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2745</build>
					<private>2800</private>
				</version>
		</file_test>
		<file_test id="wft-566" comment="The version of srv.sys is less than 4.0.1381.7214" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\Drivers\SRV.SYS</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7214</private>
				</version>
		</file_test>
		<file_test id="wft-567" comment="the version of rpcss.dll is less than 4.0.1381.7203" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>4</major>
					<minor>0</minor>
					<build>1381</build>
					<private>7224</private>
				</version>
		</file_test>
		<file_test id="wft-568" comment="the version of rpcss.dll is less than 5.0.2195.6810" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\rpcss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6810</private>
				</version>
		</file_test>
		<file_test id="wft-569" comment="the version of quartz.dll is less than 6.1.5.132" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\quartz.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>1</minor>
					<build>5</build>
					<private>132</private>
				</version>
		</file_test>
		<file_test id="wft-57" comment="the version of sqlvdi.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\SharedCode</component>
					<component type="literal">sqlvdi.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-570" comment="the version of kernel32.dll is less than 5.0.2195.6011" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\kernel32.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6011</private>
				</version>
		</file_test>
		<file_test id="wft-58" comment="the version of impprov.dll is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">impprov.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>650</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-59" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dbmsrpcn.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>213</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-6" comment="the version of msphlpr.dll is less than 3.0.1200.408" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">Program Files\Microsoft ISA Server\msphlpr.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>3</major>
					<minor>0</minor>
					<build>1200</build>
					<private>408</private>
				</version>
		</file_test>
		<file_test id="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xpweb70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>778</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-61" comment="File msgprox.dll version3 is less than 765" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">msgprox.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\SharedCode</component>
					<component type="literal">replprov.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>798</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-63" comment="File replrec.dll version3 is less than 765" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">replrec.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-64" comment="File sqlvdi.dll version3 is less than 765" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlvdi.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xpqueue.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xprepl.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xplog70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xpweb70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>606</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xpstar.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>628</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-7" comment="the version of w3proxy.dll is less than 2.0.390.16" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">%windir%\InetPub\scripts\proxy\w3proxy.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2</major>
					<minor>0</minor>
					<build>390</build>
					<private>16</private>
				</version>
		</file_test>
		<file_test id="wft-70" comment="File console.exe version3 is less than 818" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">console.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-71" comment="File dbmslpcn.dll version3 is less than 818" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\dbmslpcn.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>818</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-72" comment="File sqlmap70.dll version3 is less than 811" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlmap70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>811</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-73" comment="File sqlrepss.dll version3 is less than 765" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlrepss.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>765</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-76" comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component" operator="equals">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\System32\Ntoskrnl.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>1</minor>
					<build>2600</build>
					<private>160</private>
				</version>
		</file_test>
		<file_test id="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">ums.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>816</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">odsole70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>800</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-8" comment="the version of wkssvc.dll is less than 5.00.2195.6862" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wkssvc.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>00</minor>
					<build>2195</build>
					<private>6862</private>
				</version>
		</file_test>
		<file_test id="wft-85" comment="File odsole70.dll Version3 is less than 223" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">odsole70.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>223</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-86" comment="File xpqueue.dll Version3 is less than 223" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xpqueue.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>223</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-87" comment="File xprepl.dll Version3 is less than 223" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xprepl.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>223</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-88" comment="File xpstar.dll Version3 is less than 223" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">xpstar.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>2000</major>
					<minor>80</minor>
					<build>223</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-89" comment="File sqlservr.exe version3 greater than or equal to 384" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
					<component type="literal">sqlservr.exe</component>
				</path>
				<version datatype="version" operator="greater than or equal">
					<major>2000</major>
					<minor>80</minor>
					<build>384</build>
					<private>0</private>
				</version>
		</file_test>
		<file_test id="wft-90" comment="the version of mshtml.dll is less than 5.00.3526.800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3526</build>
					<private>800</private>
				</version>
		</file_test>
		<file_test id="wft-91" comment="the version of mshtml.dll is less than 5.00.3813.800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>3813</build>
					<private>800</private>
				</version>
		</file_test>
		<file_test id="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>50</minor>
					<build>4937</build>
					<private>800</private>
				</version>
		</file_test>
		<file_test id="wft-93" comment="the version of mshtml.dll is less than 6.00.2737.800" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2737</build>
					<private>800</private>
				</version>
		</file_test>
		<file_test id="wft-94" comment="the version of mshtml.dll is less than 6.00.2800.1400" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>2800</build>
					<private>1400</private>
				</version>
		</file_test>
		<file_test id="wft-95" comment="the version of mshtml.dll is less than 6.00.3790.118" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\mshtml.dll</component>
				</path>
				<version datatype="version" operator="less than">
					<major>6</major>
					<minor>0</minor>
					<build>3790</build>
					<private>118</private>
				</version>
		</file_test>
		<file_test id="wft-98" comment="the version of wins.exe is less than 5.0.2195.6870" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<path datatype="component">
					<component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
					<component type="literal">\system32\wins.exe</component>
				</path>
				<version datatype="version" operator="less than">
					<major>5</major>
					<minor>0</minor>
					<build>2195</build>
					<private>6870</private>
				</version>
		</file_test>
		<metabase_test id="wmt-2" comment="SmartHTML interpreter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<key>LM\W3SVC</key>
				<id datatype="int">6014</id>
				<data operator="pattern match">^.*ssinc\.dll.*$</data>
		</metabase_test>
		<metabase_test id="wmt-201" comment="asp.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<key>LM\W3SVC</key>
				<id datatype="int" operator="equals">6014</id>
				<data operator="pattern match">^.*asp\.dll.*$</data>
		</metabase_test>
		<metabase_test id="wmt-202" comment="FTP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<key operator="pattern match">^LM\\MSFTPSVC\\.*$</key>
				<id datatype="int" operator="equals">1016</id>
				<data datatype="int" operator="not equal">4</data>
		</metabase_test>
		<metabase_test id="wmt-203" comment="ism.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<key>LM\W3SVC</key>
				<id datatype="int" operator="equals">6014</id>
				<data operator="pattern match">^.*ism\.dll.*$</data>
		</metabase_test>
		<metabase_test id="wmt-205" comment="idq.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<key>LM\W3SVC</key>
				<id datatype="int" operator="equals">6014</id>
				<data operator="pattern match">^.*idq\.dll.*$</data>
		</metabase_test>
		<metabase_test id="wmt-206" comment="Negotiate is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<key>LM\W3SVC</key>
				<id datatype="int">6032</id>
				<data operator="pattern match">.*Negotiate.*</data>
		</metabase_test>
		<metabase_test id="wmt-207" comment="Permanent redirects enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<key operator="pattern match">LM\\W3SVC\\/d*\\ROOT</key>
				<id datatype="int">6011</id>
				<data operator="pattern match">^http:*,PERMANENT,*</data>
		</metabase_test>
		<metabase_test id="wmt-5" comment="SSL is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<key operator="pattern match">^LM\\W3SVC\\.*$</key>
				<id datatype="int">5506</id>
		</metabase_test>
		<registry_test id="wrt-1" comment="Windows 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
				<value operator="equals">5.0</value>
		</registry_test>
		<registry_test id="wrt-10" comment="the patch kb840374 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840374</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-100" comment="MDAC 2.5 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
				<value operator="pattern match">^2\.5.*$</value>
		</registry_test>
		<registry_test id="wrt-101" comment="MDAC 2.6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
				<value operator="pattern match">^2\.6.*$</value>
		</registry_test>
		<registry_test id="wrt-102" comment="MDAC 2.7 (RTM) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
				<value operator="pattern match">^2\.70.*$</value>
		</registry_test>
		<registry_test id="wrt-103" comment="MDAC 2.7 (SP1) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
				<value operator="pattern match">^2\.71.*$</value>
		</registry_test>
		<registry_test id="wrt-104" comment="MDAC 2.8 (RTM) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
				<value operator="pattern match">^2\.8.*$</value>
		</registry_test>
		<registry_test id="wrt-105" comment="ISA Server 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server</key>
				<name>VersionMajor</name>
				<value operator="equals">3</value>
		</registry_test>
		<registry_test id="wrt-106" comment="HTTP connection reuse is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\MSExchangeWEB\DAV</key>
				<name>ReuseConnections</name>
				<value operator="equals">0</value>
		</registry_test>
		<registry_test id="wrt-107" comment="Microsoft Firewall Service is not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Fwsrv</key>
				<name>Start</name>
				<value operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-108" comment="H.323 filter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Fpc\\Arrays\\\{[^\\]+\}\\Extensions\\Proxy-Plugins\\\{FE440D49-AB26-11D2-A101-00C04FB6CFB6\}$</key>
				<name>msFPCEnabled</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-109" comment="the patch KB832759 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Exchange Server 2003\SP1\832759</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server SP</key>
				<name operator="equals">DisplayName</name>
				<value operator="equals">Microsoft ISA Server 2000 Updates</value>
		</registry_test>
		<registry_test id="wrt-110" comment="the patch q832483 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\DataAccess\Q832483</key>
				<name>IsInstalled</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-111" comment="the patch q832483 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB832483</key>
				<name>Installed</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-112" comment="the patch q816458 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\291</key>
				<name>Installed</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Exchange\Setup</key>
				<name>Services Version</name>
				<value operator="equals">65</value>
		</registry_test>
		<registry_test id="wrt-12" comment="the HCP Protocol is registered" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CLASSES_ROOT</hive>
				<key>HCP</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-120" comment="ActiveX controls are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1200</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-121" comment="ActiveX controls are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1200</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-125" comment="active scripting is enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1400</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-126" comment="active scripting is enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1400</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-13" comment="the patch KB888258 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\408</key>
				<name operator="equals">Kbs</name>
				<value operator="equals">KB888258</value>
		</registry_test>
		<registry_test id="wrt-132" comment="Word 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\9.0\Word\InstallRoot</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-133" comment="Word 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\10.0\Word\InstallRoot</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-137" comment="Excel 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\9.0\Excel\InstallRoot</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-138" comment="Excel 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\10.0\Excel\InstallRoot</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-14" comment="the patch KB888258 for Proxy Server 2.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888258</key>
				<name operator="equals">Installed</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-140" comment="the patch q832894 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB832894</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-141" comment="the patch q832894 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{eddbec60-89cb-44ef-8291-0850fd28ff6a}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-149" comment="the patch kb832359 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows Media Services\KB832359</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-160" comment="the Windows Media Station service is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\nsstation</key>
				<name>Start</name>
				<value operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-161" comment="the Windows Media Monitor service is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows Media Services\KB832359</key>
				<name>Start</name>
				<value operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-162" comment="Windows Media Services 4.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetShow</key>
				<name>Version</name>
				<value operator="equals">4.1</value>
		</registry_test>
		<registry_test id="wrt-165" comment="PCT support is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server</key>
				<name>Enabled</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-170" comment="Outlook Express 5.5 SP2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
				<name>Current</name>
				<value operator="equals">5,50,4807,1700</value>
		</registry_test>
		<registry_test id="wrt-171" comment="Outlook Express 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
				<name>Current</name>
				<value operator="equals">6,0,2600,0000</value>
		</registry_test>
		<registry_test id="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
				<name>Current</name>
				<value operator="equals">6,0,3790,0</value>
		</registry_test>
		<registry_test id="wrt-173" comment="Outlook Express 6 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
				<name>Current</name>
				<value operator="equals">6,0,2800,1106</value>
		</registry_test>
		<registry_test id="wrt-18" comment="Internet Explorer 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">6.00.2600.0000</value>
		</registry_test>
		<registry_test id="wrt-185" comment="the patch kb837001 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB837001</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-186" comment="the patch kb837009 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB837009</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-187" comment="the patch kb835732 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB835732</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-188" comment="the patch kb837009 is installed (installed components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2cc9d512-6db6-4f1c-8979-9a41fae88de0}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-189" comment="the patch kb828741 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828741</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-19" comment="the patch q824145 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{057997dd-71e4-43cc-b161-3f8180691a9e}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-190" comment="downloading of signed ActiveX controls is enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1001</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-191" comment="file downloads are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1803</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-192" comment="persistent cookies that are stored on your computer are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1A02</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-193" comment="per-session cookies (not stored) are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1A03</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-194" comment="per-session cookies (not stored) are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1A03</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-196" comment="machine is a member of a domain" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Netlogon</key>
				<name>Start</name>
				<value datatype="int" operator="equals">2</value>
		</registry_test>
		<registry_test id="wrt-197" comment="Outlook 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Office\10.0\Outlook\InstallRoot</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-198" comment="the patch kb828040 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
				<name>DisplayVersion</name>
				<value>10.0.4333.0</value>
		</registry_test>
		<registry_test id="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
				<name>DisplayVersion</name>
				<value>10.0.6626.0</value>
		</registry_test>
		<registry_test id="wrt-2" comment="Windows XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
				<value operator="equals">5.1</value>
		</registry_test>
		<registry_test id="wrt-202" comment="the patch q316059 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{E81659DF-28E1-4C60-B4B9-00A4BC5FA76D}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-203" comment="the patch q319282 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2D5974C5-5185-4f5b-80B6-28015ACDD74C}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-204" comment="the patch q321232 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{D7B44F3E-77D3-44C5-8E03-4222D9A18B7B}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-205" comment="the patch q323759 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{61E6EAE5-7821-4AC1-9BBD-AED032A8E273}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-206" comment="the patch q328970 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{FF4DD9CD-F25E-425a-8B5C-A2D062781FBB}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-207" comment="the patch q324929 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2757B1D6-0367-4663-877C-93ECC5C01BF6}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-208" comment="the patch q810847 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{C34F4917-ED43-439f-9023-97B0024A2B3B}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-209" comment="the patch q813489 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{F9C174E3-3E87-40bc-AA94-B8974F2B9222}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-210" comment="the patch q818529 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{f5de1b93-9d38-416b-b09e-aa85a8e84309}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-211" comment="the patch q822925 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{377483c2-e4b4-4ee8-b577-9aed264c8735}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-212" comment="the patch q828750 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{96543d59-497a-4801-a1f3-5936aacaf7b1}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-214" comment="IIS 4.0 Major Version" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\INetStp</key>
				<name>MajorVersion</name>
				<value datatype="int" operator="equals">4</value>
		</registry_test>
		<registry_test id="wrt-215" comment="IIS minor version equals 0" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\INetStp</key>
				<name>MinorVersion</name>
				<value datatype="int" operator="equals">0</value>
		</registry_test>
		<registry_test id="wrt-217" comment="Patch Q319733 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q319733</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-218" comment="Patch Q327696 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q327696</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-219" comment="Patch Q811114 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q811114</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-220" comment="Internet Explorer 6.0 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">6.0.2600.0000</value>
		</registry_test>
		<registry_test id="wrt-222" comment="SP4 or later Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="greater than or equal">Service Pack 4</value>
		</registry_test>
		<registry_test id="wrt-223" comment="IIS major version equals 5" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\INetStp</key>
				<name>MajorVersion</name>
				<value datatype="int" operator="equals">5</value>
		</registry_test>
		<registry_test id="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="pattern match">^Service Pack [3-9]|\d{2,}$</value>
		</registry_test>
		<registry_test id="wrt-225" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.50.4134.0100</value>
		</registry_test>
		<registry_test id="wrt-226" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.50.4134.0600</value>
		</registry_test>
		<registry_test id="wrt-227" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.50.4522.1800</value>
		</registry_test>
		<registry_test id="wrt-229" comment="Patch Q326886 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q326886</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-23" comment="the patch kb889293 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{839117ee-2132-4bae-a56a-42b50204c9b9}</key>
				<name operator="equals">IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-230" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.2919.800</value>
		</registry_test>
		<registry_test id="wrt-231" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.2919.3800</value>
		</registry_test>
		<registry_test id="wrt-232" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.2919.6307</value>
		</registry_test>
		<registry_test id="wrt-233" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.2920.0000</value>
		</registry_test>
		<registry_test id="wrt-234" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.3103.1000</value>
		</registry_test>
		<registry_test id="wrt-235" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.3105.0106</value>
		</registry_test>
		<registry_test id="wrt-236" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.3314.2101</value>
		</registry_test>
		<registry_test id="wrt-237" comment="the patch kb867801 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB867801</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-238" comment="Patch Q321599 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows 2000\SP4\Q321599</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-239" comment="Patch Q313450" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q313450</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-24" comment="the patch kb889293 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix</key>
				<name operator="equals">IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-240" comment="SMTP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\SMTPSVC</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-241" comment="Patch Q295534 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q295534</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-242" comment="Patch Q301625 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q301625</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-243" comment="Windows NT 4.0 Security Roll-up Package" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q299444</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2298d453-bcae-4519-bf33-1cbf3faf1524}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-246" comment="Patch Q318593 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q318593</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-247" comment="Patch Q269862 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q269862</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-248" comment="Patch Q277873 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q277873</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-249" comment="Patch Q293826 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q293826</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-25" comment="the patch kb885836 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885836</key>
				<name operator="equals">Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="equals">Service Pack 2</value>
		</registry_test>
		<registry_test id="wrt-252" comment="the patch q813489 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{F9C174E3-3E87-40bc-AA94-B8974F2B9222}</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-253" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q331953</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-254" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB823980</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-256" comment="RAS Phonebook" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Ras\CurrentVersion</key>
				<name>PathName</name>
				<value operator="equals">RASPHONE.PBK</value>
		</registry_test>
		<registry_test id="wrt-257" comment="Patch Q318138 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q318138</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-258" comment="RAS Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\RasMan</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-259" comment="Windows 2000 Security Roll-up 1 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\SP2SRP1</key>
				<name>Installed</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-260" comment="SQL Server 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\CurrentVersion</key>
				<name>CurrentVersion</name>
				<value operator="equals">8.00.194</value>
		</registry_test>
		<registry_test id="wrt-261" comment="Mixed Mode Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer</key>
				<name>LoginMode</name>
				<value datatype="int" operator="equals">2</value>
		</registry_test>
		<registry_test id="wrt-262" comment="Patch Q320206 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q320206</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-263" comment="Patch Q314147 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q314147</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-264" comment="the SNMP service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\SNMP</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-265" comment="Patch Q311967 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q311967</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-266" comment="Patch Q291845 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q291845</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-270" comment="persistent cookies that are stored on your computer are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1A02</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-271" comment="Gopher Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes</key>
				<name>gopher</name>
				<value operator="equals">gopher://</value>
		</registry_test>
		<registry_test id="wrt-272" comment="Patch Q810833 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q810833</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-273" comment="Locator Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\RPCLocator</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-274" comment="the patch q815021 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q815021</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-276" comment="ISA2000-KB816456-x86.exe" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\277</key>
				<name>Kbs</name>
				<value datatype="int" operator="equals">816456</value>
		</registry_test>
		<registry_test id="wrt-277" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB817606</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-28" comment="Win2K/XP/2003 service pack 4 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="pattern match">^Service Pack [4-9]|\d{2,}$</value>
		</registry_test>
		<registry_test id="wrt-280" comment=".hta applications are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Classes\MIME\Database\Content Type\application/hta</key>
				<name>Extension</name>
				<value operator="equals">.hta</value>
		</registry_test>
		<registry_test id="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB824146</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-283" comment="DCOM is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Ole</key>
				<name>EnableDCOM</name>
				<value operator="equals">Y</value>
		</registry_test>
		<registry_test id="wrt-284" comment="the patch q290108 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{90A2A715-D986-4EAB-8C73-4D06114EF760}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-285" comment="the patch q295106 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{754D29C1-0C97-405F-98D0-21B212CA7FF1}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-286" comment="file downloads are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1803</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-287" comment="Patch Q312895 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q312895</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-288" comment="Patch Q313829 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q313829</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-289" comment="Patch Q321599 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q321599</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="pattern match">^Service Pack [2-9]|\d{2,}$</value>
		</registry_test>
		<registry_test id="wrt-293" comment="Patch WindowsXP-KB823182-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB823182</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-294" comment="downloading of signed ActiveX controls is enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name>1001</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-295" comment="Patch Q326830 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q326830</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-296" comment="Lanman enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\lanmanserver</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">2</value>
		</registry_test>
		<registry_test id="wrt-297" comment="Patch Q323172 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q323172</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-298" comment="ActiveX Enabled In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name datatype="int">1200</name>
				<value datatype="int" operator="equals">0</value>
		</registry_test>
		<registry_test id="wrt-299" comment="Patch Q300972 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q300972</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-3" comment="a Win2K/XP/2003 service pack is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
		</registry_test>
		<registry_test id="wrt-30" comment="use machine settings rather than individual user settings" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</key>
				<name>Security_HKLM_only</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-300" comment="Terminal Server Version" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\Terminal Server</key>
				<name>ProductVersion</name>
				<value operator="equals">5.0</value>
		</registry_test>
		<registry_test id="wrt-301" comment="Patch Q324380 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q324380</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-302" comment="RDP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\RDPWD</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-304" comment="the patch kb824141 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB824141</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-305" comment="the utility manager Service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\UtilMan</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-307" comment="the messenger service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Messenger</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-308" comment="Patch KB825119 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB825119</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-309" comment="HCP Protocol" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CLASSES_ROOT</hive>
				<key>HCP</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents</key>
				<name>fp_extensions</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-310" comment="the patch kb826232 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB826232</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-312" comment="Patch Q305601 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q305601</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-314" comment="Patch Q329170 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329170</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-315" comment="SMB Signing enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\lanmanserver\parameters</key>
				<name>enablesecuritysignature</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-316" comment="Windows Media Player for Windows XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\MediaPlayer\8.0\Registration</key>
				<name>UDBVersion</name>
				<value operator="equals">8.0.0.4477</value>
		</registry_test>
		<registry_test id="wrt-317" comment="Patch wm320920_8.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm320920</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-318" comment="Patch wm308567 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm308567</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\5.0\Setup Packages</key>
				<name>Microsoft FrontPage Server Extensions 2002</name>
		</registry_test>
		<registry_test id="wrt-323" comment="Patch Q823803 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q823803</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-324" comment="Patch WindowsMedia8-KB817787-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm817787</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-325" comment="Patch Q303984 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q303984</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-326" comment="the NNTP service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\NntpSvc</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-328" comment="the patch q323255 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q323255</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-33" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\Setup Packages</key>
				<name>FrontPage 2000 Server Extensions SR</name>
		</registry_test>
		<registry_test id="wrt-331" comment="Patch isahf257 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\257</key>
				<name>Kbs</name>
				<value datatype="int" operator="equals">331066</value>
		</registry_test>
		<registry_test id="wrt-332" comment="Microsoft Firewall Service Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Fwsrv</key>
				<name>Start</name>
				<value datatype="int" operator="equals">2</value>
		</registry_test>
		<registry_test id="wrt-333" comment="Patch Q307298 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q307298</key>
				<name>IsInstalled</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-334" comment="the telnet service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\Tlntsvr</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-335" comment="Patch KB822679 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB822679</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-34" comment="SharePoint Team Services are enabled (2K, XP, 2003)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\Setup Packages</key>
				<name>SharePoint</name>
				<value operator="equals">Installed</value>
		</registry_test>
		<registry_test id="wrt-347" comment="Service Pack 6 Installed (or later)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="equals">Service Pack 6</value>
		</registry_test>
		<registry_test id="wrt-348" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.50.4134.0100</value>
		</registry_test>
		<registry_test id="wrt-349" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.50.4134.0600</value>
		</registry_test>
		<registry_test id="wrt-35" comment="Word for Windows 6.0 Converter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Wordpad</key>
				<name operator="equals">EnableLegacyConverters</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-350" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.50.4522.1800</value>
		</registry_test>
		<registry_test id="wrt-351" comment="Patch Q286045 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{A954CDD5-A95F-414F-B3FE-FBEF9D2AECEA}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-352" comment="Patch Q295106 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{754D29C1-0C97-405F-98D0-21B212CA7FF1}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-353" comment="Internet Explorer 6.0 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">6.0.2600.0000</value>
		</registry_test>
		<registry_test id="wrt-354" comment="Patch Q313675 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{716E024F-7F74-47F3-B93B-9FF7F3CBF94C}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-355" comment="Patch Q316059.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{E81659DF-28E1-4C60-B4B9-00A4BC5FA76D}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-356" comment="Patch Q319282 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Active Setup\Installed Components\{2D5974C5-5185-4f5b-80B6-28015ACDD74C}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-36" comment="the patch kb885835is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885835</key>
				<name operator="equals">Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-368" comment="Use Machine Settings" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</key>
				<name>Security_HKLM_only</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-369" comment="File Downloads Allowed In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name datatype="int">1803</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-37" comment="the patch KB885249 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885249</key>
				<name operator="equals">Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-371" comment="Run ActiveX Controls and Plugins Allowed In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
				<name datatype="int">1200</name>
				<value datatype="int" operator="not equal">3</value>
		</registry_test>
		<registry_test id="wrt-373" comment="Windows NT Service Pack 5 (or later) installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="greater than or equal">Service Pack 5</value>
		</registry_test>
		<registry_test id="wrt-375" comment="DataAccess Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
				<value operator="pattern match">^2\.5.*</value>
		</registry_test>
		<registry_test id="wrt-376" comment="Patch Q823718 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\DataAccess\Q823718</key>
				<name>IsInstalled</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-377" comment="DataAccess Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
				<value operator="pattern match">^2\.6.*</value>
		</registry_test>
		<registry_test id="wrt-38" comment="the patch KB870763 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB870763</key>
				<name operator="equals">Installed</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-382" comment="DataAccess Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DataAccess</key>
				<name>FullInstallVer</name>
				<value operator="pattern match">^2\.7.*</value>
		</registry_test>
		<registry_test id="wrt-385" comment="COM Internet Services are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Ole</key>
				<name>EnableDCOMHTTP</name>
				<value operator="equals">Y</value>
		</registry_test>
		<registry_test id="wrt-386" comment="Patch Q232449 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q232449 </key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-387" comment="Patch Q811114 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\Hotfix\Q811114</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-388" comment="Patch KB817772 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB817772</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-389" comment="Patch KB822343 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB822343</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-39" comment="If key present hyperterminal will automatically open session files" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">htfile</key>
				<name operator="pattern match">^.*$</name>
		</registry_test>
		<registry_test id="wrt-390" comment="IIS 5.1 Minor Version" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\INetStp</key>
				<name>MinorVersion</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-391" comment="Windows 98 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
				<name>Version</name>
				<value operator="equals">Windows 98</value>
		</registry_test>
		<registry_test id="wrt-392" comment="Patch 273991USA8.EXE Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\UtilMan{5c773859-bb96- 48fa-875b-6a58aae072f4}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-393" comment="NetBIOS Bind not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
				<name>Bind</name>
				<value datatype="int" operator="not equal">0</value>
		</registry_test>
		<registry_test id="wrt-394" comment="NetBIOS Export not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
				<name>Export</name>
				<value datatype="int" operator="not equal">0</value>
		</registry_test>
		<registry_test id="wrt-395" comment="NetBIOS Route not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
				<name>Route</name>
				<value datatype="int" operator="not equal">0</value>
		</registry_test>
		<registry_test id="wrt-396" comment="Windows 95 or 98 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
				<name>Version</name>
				<value operator="pattern match">^Windows.*</value>
		</registry_test>
		<registry_test id="wrt-397" comment="TCP/IP NetBIOS not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\LmHosts</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-398" comment="WINS Client binding not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip.*$</key>
				<name>NetbiosOptions</name>
				<value datatype="int" operator="not equal">2</value>
		</registry_test>
		<registry_test id="wrt-399" comment="Remote access to registry not controlled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="equals">Service Pack 1</value>
		</registry_test>
		<registry_test id="wrt-40" comment="this is an NT Workstation" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
				<name>ProductType</name>
				<value operator="equals">WinNT</value>
		</registry_test>
		<registry_test id="wrt-400" comment="the w3svc service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\w3svc</key>
				<name>Start</name>
				<value datatype="binary" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-404" comment="DirectX 8.1x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
				<value operator="pattern match">^4\.08\.01.*$</value>
		</registry_test>
		<registry_test id="wrt-405" comment="DirectX 8.2 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
				<value operator="pattern match">^4\.08\.02.*$</value>
		</registry_test>
		<registry_test id="wrt-406" comment="DirectX 9.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
				<value operator="pattern match">^4\.09.*$</value>
		</registry_test>
		<registry_test id="wrt-407" comment="the patch kb839643 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-408" comment="Patch DirectX82-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643-DirectX82</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-409" comment="Patch DirectX90-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643-DirectX9</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-41" comment="this is an NT Server (stand-alone)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
				<name>ProductType</name>
				<value operator="pattern match">^.*ServerNT.*$</value>
		</registry_test>
		<registry_test id="wrt-410" comment="Win2K/XP/2003 service pack 1 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="pattern match">^Service Pack [1-9]|\d{2,}$</value>
		</registry_test>
		<registry_test id="wrt-413" comment="Windows XP or Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
				<value operator="pattern match">^5\.[1-2]$</value>
		</registry_test>
		<registry_test id="wrt-42" comment="this is an NT Server (domain controller)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
				<name>ProductType</name>
				<value operator="pattern match">^.*LanmanNT.*$</value>
		</registry_test>
		<registry_test id="wrt-43" comment="this is an NT Terminal Server" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
				<name>ProductSuite</name>
				<value operator="equals">Terminal Server</value>
		</registry_test>
		<registry_test id="wrt-454" comment="Patch Q265714 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q265714</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-455" comment="MTS Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Transaction Server\Packages</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-456" comment="Windows NT Server 4.0, Terminal Server Edition Security Rollup Package" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q317636</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-457" comment="Microsoft Exchange 2000 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key operator="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*</key>
				<name>DisplayName</name>
				<value operator="equals">Microsoft Exchange 2000</value>
		</registry_test>
		<registry_test id="wrt-458" comment="Patch Q316056 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Updates\Exchange Server 2000\SP3\Q316056</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-459" comment="Everyone group given remote access permissions" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg</key>
				<name>Everyone</name>
		</registry_test>
		<registry_test id="wrt-46" comment="the patch Windows2000-KB873339-x86-ENU.EXE is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB873339\ Filelist</key>
				<name operator="pattern match">^.*$</name>
		</registry_test>
		<registry_test id="wrt-460" comment="SQL Server 2000 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\CurrentVersion</key>
				<name>CurrentVersion</name>
				<value operator="equals">8.00.194</value>
		</registry_test>
		<registry_test id="wrt-461" comment="DirectX 7.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
				<value operator="pattern match">^4\.07.*</value>
		</registry_test>
		<registry_test id="wrt-462" comment="Patch Windows2000-KB839643-x86-ENU.EXE Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-463" comment="DirectX 8.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
				<value operator="pattern match">^4\.08\.00.*</value>
		</registry_test>
		<registry_test id="wrt-464" comment="Patch DirectX80-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX8</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-465" comment="DirectX 8.1x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
				<value operator="pattern match">^4\.08\.01.*</value>
		</registry_test>
		<registry_test id="wrt-466" comment="Patch DirectX81-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX81</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-467" comment="DirectX 8.2x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
				<value operator="pattern match">^4\.08\.02.*</value>
		</registry_test>
		<registry_test id="wrt-468" comment="Patch DirectX82-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX82</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-469" comment="DirectX 9.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\DirectX</key>
				<name>Version</name>
				<value operator="pattern match">^4\.09\.00.*</value>
		</registry_test>
		<registry_test id="wrt-470" comment="Patch DirectX90-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX9</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-471" comment="RestrictAnonymous registry value allows anonymous connections" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\LSA</key>
				<name>RestrictAnonymous</name>
				<value datatype="int" operator="equals">0</value>
		</registry_test>
		<registry_test id="wrt-472" comment="Veritas Backup Exec 8.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>\Software\VERITAS\Backup Exec\Server</key>
				<name>CurrentVersion</name>
				<value operator="equals">8.5</value>
		</registry_test>
		<registry_test id="wrt-475" comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP1\KB824105\Filelist</key>
				<name operator="equals">installed</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-476" comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed on XP SP1" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB824105\Filelist</key>
				<name operator="equals">installed</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-477" comment="the patch Q329115 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329115</key>
				<name>Installed</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-478" comment="the patch Q811493 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q811493</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-479" comment="POSIX is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SYSTEM\CurrentControlSet\Control\Session Manager\Subsystem</key>
				<name operator="equals">Posix</name>
		</registry_test>
		<registry_test id="wrt-480" comment="the patch kb841872 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841872</key>
				<name>Installed</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-481" comment="the patch kb842526 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB842526</key>
				<name>Installed</name>
				<value datatype="int" operator="equals"/>
		</registry_test>
		<registry_test id="wrt-482" comment="the patch kb840315 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840315</key>
				<name>Installed</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-483" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB841873</key>
				<name>Installed</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-484" comment="the patch q841373 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q841373</key>
				<name>Installed</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-485" comment="MaxClientRequestBufferData less than or equal to 16384" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>System\CurrentControlSet\Services\w3svc\parameters</key>
				<name>MaxClientRequestBufferData</name>
				<value operator="less than or equal">16384</value>
		</registry_test>
		<registry_test id="wrt-488" comment="the patch kb839645 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839645</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-490" comment="Active Desktop  is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4395}</key>
				<name>IsInstalled</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-491" comment="HTML Help is registered" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Classes\ITSProtocol</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-492" comment="Patch IE-KB841873-WindowsNT4sp6-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{bfb56e60-5895-496c-bd6b-459b97142e4c}</key>
				<name>IsInstalled</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-493" comment="Patch KB821557 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB821557</key>
				<name>Installed</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-494" comment="the patch kb823353 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CLASSES_ROOT</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\kb823353</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-495" comment="all users have the preview pane disabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_USERS</hive>
				<key operator="pattern match">^S-[-0-9]+\\Identities\\\{[-0-9A-Z]+\}\\Software\\Microsoft\\Outlook\ Express\\5\.0\\Mail$</key>
				<name>ShowHybridView</name>
				<value>0</value>
		</registry_test>
		<registry_test id="wrt-499" comment="the patch js56nen.exe (5.6.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
				<name>Version</name>
				<value>5,6,0,8513</value>
		</registry_test>
		<registry_test id="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">6.00.2800.1106</value>
		</registry_test>
		<registry_test id="wrt-500" comment="the patch js56nen.exe (5.1.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
				<name>Version</name>
				<value>5,1,0,8513</value>
		</registry_test>
		<registry_test id="wrt-501" comment="the patch js56nen.exe (5.5.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
				<name>Version</name>
				<value>5,5,0,8513</value>
		</registry_test>
		<registry_test id="wrt-502" comment="Patch Q328310 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q328310</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-503" comment="Patch Q329414 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329414</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-504" comment="Exchange 5.5 with SP4 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Exchange\Setup</key>
				<name>ServicePackBuild</name>
				<value>2653</value>
		</registry_test>
		<registry_test id="wrt-505" comment="the  patch kb842436 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Exchange Server 5.5\SP5\842436a</key>
				<name>IsInstalled</name>
				<value>2</value>
		</registry_test>
		<registry_test id="wrt-506" comment="Outlook Web Access exists" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\MSExchangeweb</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-51" comment="Internet Explorer 6 Service Pack 1 for Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">6.00.3790.0000</value>
		</registry_test>
		<registry_test id="wrt-512" comment="the patch KB833987 is installed (for Windows Server 2003)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB833987</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-513" comment="the patch KB833987 is installed (for Windows XP)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB833987</key>
				<name>Installed</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-514" comment="Microsoft Office XP Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
				<name>DisplayVersion</name>
				<value>10.0.4330.0</value>
		</registry_test>
		<registry_test id="wrt-515" comment="Microsoft Office 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90110409-6000-11D3-8CFE-0150048383C9}</key>
				<name>DisplayVersion</name>
				<value>11.0.6252.7</value>
		</registry_test>
		<registry_test id="wrt-516" comment="Patch KB873378 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Patches\9FEC06657760FC84499ED532196D45EE2</key>
				<name>Security Update for Office 2003: Wordperfect 5.x Converter (KB873378)</name>
				<value>Installed</value>
		</registry_test>
		<registry_test id="wrt-517" comment="Patch KB838905 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Patches\FC3FF5BA5FE5D1B4A9B9CD3698A34B89</key>
				<name operator="pattern match">.*</name>
				<value>Installed</value>
		</registry_test>
		<registry_test id="wrt-518" comment="The patch KB830348 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Updates\Visual Studio\7.1\M8303481037</key>
				<name>Installed</name>
				<value operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-519" comment="Microsoft Visual Studio .NET 2003 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\VisualStudio\7.1</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-521" comment="Project Professional 2003 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0150048383C9}</key>
				<name>DisplayVersion</name>
				<value>11.0.5614.0</value>
		</registry_test>
		<registry_test id="wrt-522" comment="Patch KB838344 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040B30900063D11C\Patches\69B0450262BC7F44E8D4B683A49E437A</key>
				<name>Installed</name>
		</registry_test>
		<registry_test id="wrt-523" comment="Windows Project Professional 2002 Service Pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0050048383C9}</key>
				<name>DisplayVersion</name>
				<value operator="equals">10.0.8326.0</value>
		</registry_test>
		<registry_test id="wrt-524" comment="Patch KB831931 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040B30900063D11C8EF00054038389C\Patches\1F6752D69ABCD9F4B8021B9163826CAC</key>
				<name>Installed</name>
		</registry_test>
		<registry_test id="wrt-525" comment="Visio Professional 2002 with service pack 2" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6D54-11D4-BEE3-00C04F990354}</key>
				<name>DisplayVersion</name>
				<value operator="equals">10.2.5110</value>
		</registry_test>
		<registry_test id="wrt-526" comment="Patch KB831932 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040150945D64D11EB3E000CF4993045\Patches\A75085E78F7F14244A464F09F6543C6C</key>
				<name>Installed</name>
		</registry_test>
		<registry_test id="wrt-527" comment="Visio Professional 2003 is Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6000-11D3-8CFE-0150048383C9}</key>
				<name>DisplayVersion</name>
				<value operator="equals">11.0.3216.5614</value>
		</registry_test>
		<registry_test id="wrt-528" comment="Patch KB838345 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040150900063D11C8EF10054038389C\Patches\6B94DD4A71ECBDE43822F9D47D963102</key>
				<name>Installed</name>
		</registry_test>
		<registry_test id="wrt-529" comment="Microsoft Office 2000 Premium Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00000409-78E1-11D2-B60F-006097C998E7}</key>
				<name>DisplayVersion</name>
				<value>9.00.9327</value>
		</registry_test>
		<registry_test id="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.50.4807.2300</value>
		</registry_test>
		<registry_test id="wrt-530" comment="the patch kb873380 for Office 2000 SP3 is installed " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Patches\A1334AC428B43BF4E9547C55D3DFE977</key>
				<name operator="pattern match">.*</name>
				<value>Installed</value>
		</registry_test>
		<registry_test id="wrt-531" comment="Microsoft Visual Studio .NET 2002 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\VisualStudio\7.0</key>
				<name operator="pattern match">.*</name>
		</registry_test>
		<registry_test id="wrt-532" comment="Patch KB830348 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040F50095765D115AF4000972A8B18B\Patches\4A3C9366F1471A7479BB3FDBC1FE3B31</key>
				<name>Installed</name>
		</registry_test>
		<registry_test id="wrt-533" comment="Patch KB832332 installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040820900063D11C\Patches\4461EFFBCC9338645A85657DBDEB9E61</key>
				<name>Installed</name>
		</registry_test>
		<registry_test id="wrt-534" comment="the patch q833989 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{dc0d5f50-5F0b-46bf-8683-93ac61c67001}</key>
				<name>ComponentID</name>
				<value operator="equals">Q833989</value>
		</registry_test>
		<registry_test id="wrt-535" comment="Microsoft Office 2000 Professional Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00010409-78E1-11D2-B60F-006097C998E7}</key>
				<name>DisplayVersion</name>
				<value>9.00.9327</value>
		</registry_test>
		<registry_test id="wrt-536" comment="Windows NT Service Pack 6a is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q246009</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-537" comment="the patch q841356 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>Software\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841356</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="pattern match">^Service Pack [0-4]$</value>
		</registry_test>
		<registry_test id="wrt-539" comment="Win2K/XP/2003 service pack 5 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CSDVersion</name>
				<value operator="pattern match">^Service Pack [5-9]|\d{2,}$</value>
		</registry_test>
		<registry_test id="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.3700.1000</value>
		</registry_test>
		<registry_test id="wrt-541" comment="WebDav is disabled(for iis 5.0)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\W3SVC\Parameters</key>
				<name>DisableWebDAV</name>
				<value datatype="int">1</value>
		</registry_test>
		<registry_test id="wrt-542" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885881</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-544" comment="the patch WindowsServer2003-KB885881-ia64-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885881</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840987</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-548" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB883935</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-549" comment="the patch KB824151 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB824151</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.3502.1000</value>
		</registry_test>
		<registry_test id="wrt-550" comment="Windows ME Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
				<name>Version</name>
				<value operator="equals">Windows ME</value>
		</registry_test>
		<registry_test id="wrt-551" comment="the patch KB841533 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841533</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-552" comment="the patch WindowsServer2003-KB883935-x86-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB883935</key>
				<name>Installed</name>
				<value>1</value>
		</registry_test>
		<registry_test id="wrt-553" comment="the patch q873376 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873376</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Classes\CompressedFolder</key>
				<name>FriendlyTypeName</name>
				<value operator="pattern match">*zipfldr.dll*</value>
		</registry_test>
		<registry_test id="wrt-555" comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883935</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-556" comment="Patch WindowsNT4OptionPack-KB883935-x86-enu.EXE" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883935</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-558" comment="Patch KB873350 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873350</key>
				<name>File</name>
				<value datatype="binary" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-559" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie501sp3-20040929.121357</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">5.00.3315.1000</value>
		</registry_test>
		<registry_test id="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie501sp4-20040929.111451</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Active Setup\Installed Components\{ 3e7bb08a-a7a3-4692-8eac-ac5e7895755b}</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie6-20040929.115007 </key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-564" comment="the patch kb834707  is installed (Installed Components key) " xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707</key>
				<name>IsInstalled</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-565" comment="Internet Explorer 6 Service Pack 2 for XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Internet Explorer</key>
				<name>Version</name>
				<value operator="equals">6.00.2900.2180</value>
		</registry_test>
		<registry_test id="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_CURRENT_USER</hive>
				<key operator="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings$</key>
				<name>DisableCachingOfSSLPages</name>
				<value operator="not equal">1</value>
		</registry_test>
		<registry_test id="wrt-569" comment="Patch Q817606 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q817606</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-570" comment="Patch Q823980 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q823980</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-571" comment="Patch Q19696 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q19696</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-60" comment="the patch q824145 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB824245</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-61" comment="Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
				<value operator="equals">5.2</value>
		</registry_test>
		<registry_test id="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_CLASSES_ROOT</hive>
				<key operator="equals">telnet\shell\open</key>
				<name operator="equals">command</name>
				<value operator="equals">C:\Program Files\Windows NT\hypertrm.exe /t %1</value>
		</registry_test>
		<registry_test id="wrt-70" comment="64-Bit version of Windows is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
				<name>PROCESSOR_ARCHITECTURE</name>
				<value operator="equals">ia64</value>
		</registry_test>
		<registry_test id="wrt-71" comment="the workstation service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\lanmanworkstation</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-72" comment="32-Bit version of Windows is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
				<name>PROCESSOR_ARCHITECTURE</name>
				<value operator="equals">x86</value>
		</registry_test>
		<registry_test id="wrt-77" comment="Windows NT 4.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
				<name>CurrentVersion</name>
				<value datatype="int" operator="equals">4.0</value>
		</registry_test>
		<registry_test id="wrt-83" comment="the patch q828035 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828035</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-86" comment="the patch q828748 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828749</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-88" comment="the patch q810217 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB810217</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-9" comment="Microsoft Proxy Server 2.0 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive operator="equals">HKEY_LOCAL_MACHINE</hive>
				<key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Proxy Server</key>
				<name operator="equals">Microsoft Proxy Server</name>
		</registry_test>
		<registry_test id="wrt-97" comment="the patch kb830352 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB830352</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
		<registry_test id="wrt-98" comment="the wins service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SYSTEM\CurrentControlSet\Services\wins</key>
				<name>Start</name>
				<value datatype="int" operator="not equal">4</value>
		</registry_test>
		<registry_test id="wrt-99" comment="the patch kb828028 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
				<hive>HKEY_LOCAL_MACHINE</hive>
				<key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828028</key>
				<name>Installed</name>
				<value datatype="int" operator="equals">1</value>
		</registry_test>
	</tests>
</oval>
