<?xml version="1.0" encoding="UTF-8"?>
<oval xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns:redhat="http://oval.mitre.org/XMLSchema/oval#redhat" xmlns:solaris="http://oval.mitre.org/XMLSchema/oval#solaris" xmlns:windows="http://oval.mitre.org/XMLSchema/oval#windows" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval oval-schema.xsd http://oval.mitre.org/XMLSchema/oval#redhat redhat-schema.xsd http://oval.mitre.org/XMLSchema/oval#solaris solaris-schema.xsd http://oval.mitre.org/XMLSchema/oval#windows windows-schema.xsd" oval:schemaVersion="3.0" windows:schemaVersion="3.0" redhat:schemaVersion="3.0" solaris:schemaVersion="3.0" oval:timeStamp="20050112134741">
	<definitions>
		<definition id="OVAL2" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mutt</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0140</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-201" comment="balsa version is less than 2.0.6-2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-201" comment="/usr/bin/balsa is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>CUPS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0195</cveid>
			<dates>
				<created date="2003-08-19"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-202" comment="cups version is less than 1.1.17-13.3" />
				</software>
				<configuration>
					<criterion test_ref="rlt-201" comment="cupsd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL7" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>kcms_configure</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0594</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-201" comment="File kcms_configure exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL9" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>libnsl</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0391</cveid>
			<dates>
				<created date="2003-01-28"/>
			</dates>
			<description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" />
					<criterion test_ref="cmp-205" negate="true" comment="Patches 108827-30 and 108901-06" />
				</software>
				<configuration>
					<criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL10" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>xlock</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0652</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-204" comment="File xlock exists" />
					<criterion test_ref="spt-203" negate="true" comment="Patch 108652-38 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-209" comment="File xlock SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL11" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>snmpdx</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0796</cveid>
			<dates>
				<created date="2002-09-25"/>
			</dates>
			<description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-205" comment="File snmpdx exists" />
					<criterion test_ref="spt-204" negate="true" comment="Patch 108869-16 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-203" comment="snmpdx running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL12" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0026</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL14" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Xsun</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0158</cveid>
			<dates>
				<created date="2002-08-23"/>
			</dates>
			<description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-206" comment="File Xsun exists" />
					<criterion test_ref="spt-205" negate="true" comment="Patch 108652-52 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-210" comment="File Xsun SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL15" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0677</cveid>
			<dates>
				<created date="2003-01-31"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-206" negate="true" comment="Patch 110286-09 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL16" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0079</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL17" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0023</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL18" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Matthew Burton</submitter>
			</contributors>
			<cveid status="CVE">2002-0070</cveid>
			<dates>
				<created date="2004-09-15"/>
				<modified date="2004-09-16">Completing an initial submission.</modified>
				<modified date="2004-10-19">done</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-13">INTERIM</status_change>
				<status_change date="2004-10-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-490" comment="the version of shell32.dll is less than 4.0.1381.7116" />
					<criterion test_ref="wrt-288" negate="true" comment="Patch Q313829 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL19" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CAN">2002-0189</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL20" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
			</contributors>
			<cveid status="CAN">2003-0715</cveid>
			<dates>
				<created date="2004-11-02"/>
				<modified date="2004-11-02"></modified>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-568" comment="the version of rpcss.dll is less than 5.0.2195.6810" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL22" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2002-0147</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun.</description>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL23" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0026</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL24" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>FTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0073</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-202" comment="FTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL25" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0079</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL26" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Network Connection Manager (NCM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Christine Walzer</submitter>
				<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
			</contributors>
			<cveid status="CVE">2002-0720</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
					<criterion test_ref="wft-207" comment="the version of netman.dll is less than 5.0.2195.5974" />
					<criterion test_ref="wrt-229" negate="true" comment="Patch Q326886 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL27" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0193</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-208" comment="the version of mshtml.dll is less than 5.0.3504.2500" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-215" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL28" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>skk</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0539</cveid>
			<dates>
				<created date="2003-09-04"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-216" comment="Vulnerable config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL29" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0364</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.</description>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-209" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" />
					<criterion test_ref="wrt-238" negate="true" comment="Patch Q321599 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL30" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2002-0055</cveid>
			<dates>
				<created date="2003-05-20"/>
				<modified date="2004-03-30">Changed the registry key in question for the SMTP enabled check to SMTPSVC from SMTP.</modified>
			</dates>
			<description>SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 to cause a denial of service via a command with a malformed data transfer (BDAT) request</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-210" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" />
					<criterion test_ref="wrt-239" negate="true" comment="Patch Q313450" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL31" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0033</cveid>
			<dates>
				<created date="2003-01-31"/>
			</dates>
			<description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
					<criterion test_ref="spt-207" negate="true" comment="Patch 110896-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL32" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0026</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL33" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Xsun</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0158</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-206" comment="File Xsun exists" />
					<criterion test_ref="spt-208" negate="true" comment="Patch 108376-38 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-210" comment="File Xsun SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL34" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>whodo</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2001-1076</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-209" comment="File whodo exists" />
					<criterion test_ref="spt-209" negate="true" comment="Patch 111600-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-219" comment="File whodo SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL35" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>FTP</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0073</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters</description>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-202" comment="FTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL37" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2001-0333</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-211" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" />
					<criterion test_ref="wrt-241" negate="true" comment="Patch Q295534 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-243" negate="true" comment="Windows NT 4.0 Security Roll-up Package" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL38" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0051</cveid>
			<dates>
				<created date="2003-05-13"/>
			</dates>
			<description>Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" />
					<criterion test_ref="wft-212" comment="the version of srvsvc.dll is less than 5.00.2195.4980" />
					<criterion test_ref="wrt-246" negate="true" comment="Patch Q318593 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL39" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0150</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL40" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0023</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL41" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>rpc.rwalld</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0573</cveid>
			<dates>
				<created date="2003-01-30"/>
			</dates>
			<description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-210" comment="File rpc.rwalld exists" />
					<criterion test_ref="spt-210" negate="true" comment="Patch 112899-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-221" comment="File rpc.rwalld executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL42" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>libnsl</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0391</cveid>
			<dates>
				<created date="2003-01-02"/>
			</dates>
			<description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" />
					<criterion test_ref="cmp-223" negate="true" comment="Patches 106942-22 and 108451-06" />
				</software>
				<configuration>
					<criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL43" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0084</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL44" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2000-0884</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-213" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" />
					<criterion test_ref="wrt-247" negate="true" comment="Patch Q269862 Installed" />
					<criterion test_ref="wrt-248" negate="true" comment="Patch Q277873 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL45" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0071</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL46" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0074</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL47" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>whodo</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2001-1076</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-209" comment="File whodo exists" />
					<criterion test_ref="spt-213" negate="true" comment="Patch 111826-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-219" comment="File whodo SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL48" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0088</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL49" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2003-1326</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-230" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-214" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-252" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL50" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1, or Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0023</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-215" comment="the version of mshtml.dll is less than 5.0.3502.4856" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL52" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>EOG</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0165</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-205" comment="eog version is less than 2.2.0-2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-232" comment="eog is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL54" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2003-0081</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL55" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0159</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL56" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>rpc.yppasswdd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0779</cveid>
			<dates>
				<created date="2002-08-30"/>
			</dates>
			<description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-212" comment="File rpc.yppasswdd exists" />
					<criterion test_ref="spt-214" negate="true" comment="Patch 111596-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-204" comment="rpc.yppasswdd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL57" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2003-1328</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality.</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL58" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0075</cveid>
			<dates>
				<created date="2003-08-20"/>
			</dates>
			<description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL59" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CAN">2002-1561</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-217" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" />
					<criterion test_ref="wrt-253" negate="true" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" />
					<criterion test_ref="wrt-254" negate="true" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL60" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0088</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL61" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0366</cveid>
			<dates>
				<created date="2003-04-04"/>
			</dates>
			<description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wrt-256" comment="RAS Phonebook" />
					<criterion test_ref="wft-218" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" />
					<criterion test_ref="wrt-257" negate="true" comment="Patch Q318138 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL62" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>mibiisa</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0797</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-213" comment="File mibiisa exists" />
					<criterion test_ref="spt-215" negate="true" comment="Patch 107709-19 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-205" comment="mibiisa running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL63" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0366</cveid>
			<dates>
				<created date="2003-04-04"/>
			</dates>
			<description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-256" comment="RAS Phonebook" />
					<criterion test_ref="wft-219" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" />
					<criterion test_ref="wrt-257" negate="true" comment="Patch Q318138 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL64" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0018</cveid>
			<dates>
				<created date="2003-05-13"/>
				<modified date="2004-08-04"></modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-220" comment="File %windir%\system32\netlogon.dll version is less than 5.00.0893.1105" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL65" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>kcms_configure</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0594</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-201" comment="File kcms_configure exists" />
					<criterion test_ref="spt-216" negate="true" comment="Patch 107337-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL66" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2003-0223</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL67" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0089</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
					<criterion test_ref="spt-217" negate="true" comment="Patch 110453-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL68" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0089</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
					<criterion test_ref="spt-218" negate="true" comment="Patch 108721-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL69" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0356</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL70" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>dtspcd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0803</cveid>
			<dates>
				<created date="2002-08-23"/>
			</dates>
			<description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary command</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-214" comment="File dtspcd exists" />
					<criterion test_ref="spt-219" negate="true" comment="Patch 108949-07 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-239" comment="File dtspcd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL71" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
			</contributors>
			<cveid status="CVE">2001-0344</cveid>
			<dates>
				<created date="2003-06-24"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-222" comment="File sqlservr.exe version3 is less than 296" />
				</software>
				<configuration>
					<criterion test_ref="wrt-261" comment="Mixed Mode Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL72" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0147</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun.</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL73" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0357</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL74" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>dtspcd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0803</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary command</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-214" comment="File dtspcd exists" />
					<criterion test_ref="spt-220" negate="true" comment="Patch 106934-04 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-239" comment="File dtspcd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL75" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0428</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the DCERPC dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL76" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0367</cveid>
			<dates>
				<created date="2003-04-04"/>
			</dates>
			<description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-223" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" />
					<criterion test_ref="wrt-262" negate="true" comment="Patch Q320206 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL77" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-0023</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL78" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2001-0333</cveid>
			<dates>
				<created date="2003-10-10"/>
				<modified date="2004-08-04"></modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-224" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL79" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>rpc.rwalld</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0573</cveid>
			<dates>
				<created date="2003-01-30"/>
			</dates>
			<description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-210" comment="File rpc.rwalld exists" />
					<criterion test_ref="spt-221" negate="true" comment="Patch 112846-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-221" comment="File rpc.rwalld executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL80" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0678</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-222" negate="true" comment="Patch 107893-19 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL81" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0148</cveid>
			<dates>
				<created date="2003-08-20"/>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL82" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CAN">2001-0509</cveid>
			<dates>
				<created date="2003-08-27"/>
			</dates>
			<description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-225" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" />
					<criterion test_ref="wft-59" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" />
					<criterion test_ref="wft-89" negate="true" comment="File sqlservr.exe version3 greater than or equal to 384" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL83" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Yi-Fang Koh</submitter>
				<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
			</contributors>
			<cveid status="CAN">2001-0542</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CAN-2001-0879</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-227" comment="File sqlservr.exe version3 less than 428" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL84" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0429</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL86" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>lbxproxy</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0090</cveid>
			<dates>
				<created date="2002-08-30"/>
			</dates>
			<description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-215" comment="File lbxproxy exists" />
					<criterion test_ref="spt-223" negate="true" comment="Patch 108652-51 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL87" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CAN">2002-0013</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL88" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0430</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL89" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Multiple UNC Provider (MUP)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
			</contributors>
			<cveid status="CVE">2002-0151</cveid>
			<dates>
				<created date="2003-05-13"/>
			</dates>
			<description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-229" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" />
					<criterion test_ref="wrt-265" negate="true" comment="Patch Q311967 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL90" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
			</contributors>
			<cveid status="CVE">2001-0151</cveid>
			<dates>
				<created date="2003-10-10"/>
				<modified date="2004-10-20">corrected configuration criterion</modified>
				<status_change date="2004-10-20">INTERIM</status_change>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-230" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" />
					<criterion test_ref="wrt-266" negate="true" comment="Patch Q291845 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-541" negate="true" comment="WebDav is disabled(for iis 5.0)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL91" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0677</cveid>
			<dates>
				<created date="2003-01-31"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-222" negate="true" comment="Patch 107893-19 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL92" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Harvey Rubinovitz</submitter>
				<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
			</contributors>
			<cveid status="CVE">2002-0148</cveid>
			<dates>
				<created date="2003-10-10"/>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL94" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mibiisa</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0797</cveid>
			<dates>
				<created date="2002-09-25"/>
			</dates>
			<description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-213" comment="File mibiisa exists" />
					<criterion test_ref="spt-204" negate="true" comment="Patch 108869-16 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-205" comment="mibiisa running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL95" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Tiffany Bergeron</submitter>
				<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
			</contributors>
			<cveid status="CVE">2002-0149</cveid>
			<dates>
				<created date="2004-01-14"/>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL96" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2002-0078</cveid>
			<dates>
				<created date="2003-11-12"/>
				<modified date="2004-03-04">Added the configuration check to see if cookies are enabled by the current user when local machine settings are not in use.</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability</description>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-231" comment="the version of mshtml.dll is less than 6.0.2715.400" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-250" comment="cookies are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL97" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0084</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL98" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CAN">2002-0371</cveid>
			<dates>
				<created date="2003-11-12"/>
			</dates>
			<description>Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-232" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-271" comment="Gopher Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL99" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Andrew Buttner</submitter>
				<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
			</contributors>
			<cveid status="CVE">2002-0193</cveid>
			<dates>
				<created date="2004-01-27"/>
			</dates>
			<description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-215" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL101" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0431</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL102" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>rpc.yppasswdd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0779</cveid>
			<dates>
				<c