<?xml version="1.0" encoding="UTF-8"?>
<oval xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval#redhat redhat-schema.xsd http://oval.mitre.org/XMLSchema/oval#windows windows-schema.xsd http://oval.mitre.org/XMLSchema/oval#hpux hpux-schema.xsd http://oval.mitre.org/XMLSchema/oval#unix unix-schema.xsd http://oval.mitre.org/XMLSchema/oval#independent independent-schema.xsd http://oval.mitre.org/XMLSchema/oval#solaris solaris-schema.xsd http://oval.mitre.org/XMLSchema/oval oval-schema.xsd" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:redhat="http://oval.mitre.org/XMLSchema/oval#redhat" xmlns:windows="http://oval.mitre.org/XMLSchema/oval#windows" xmlns:solaris="http://oval.mitre.org/XMLSchema/oval#solaris" xmlns:hpux="http://oval.mitre.org/XMLSchema/oval#hpux">
  <generator>
    <schema_version>4.2</schema_version>
    <timestamp>20060322234339</timestamp>
  </generator>
  <definitions>
    <definition id="OVAL2" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Mutt</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
      <reference source="CVE">CVE-2003-0140</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-201" comment="balsa version is less than 2.0.6-2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-201" comment="/usr/bin/balsa is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-06-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-06-08-03:24">DRAFT</status_change>
        <status_change date="2005-06-29-06:49">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>'The Exchange 2003 Exadmin virtual directory uses only Integrated Windows Authentication.'</description>
      <reference source="MISC">2.1.6</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Corresponds to item 2.1.6 in the Exchange 2003 Benchmark</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1" comment="The exadmin HTTP virtual directory only allows Integrated Windows Authentication" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>CUPS</product>
      </affected>
      <dates>
        <submitted date="2003-08-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</description>
      <reference source="CVE">CVE-2003-0195</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-202" comment="cups version is less than 1.1.17-13.3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-201" comment="cupsd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL9" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-28-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-205" comment="Patches 108827-30 and 108901-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL10" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-203" comment="Patch 108652-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL11" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL12" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
      <reference source="CVE">CVE-2002-0026</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL14" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-205" comment="Patch 108652-52 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL15" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL16" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
      <reference source="CVE">CVE-2002-0079</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL17" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="changed IE test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
      <reference source="CVE">CVE-2002-0023</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL18" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2004-09-15-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <modified date="2004-09-16-12:00" comment="Completing an initial submission.">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2004-09-29-02:40">DRAFT</status_change>
        <status_change date="2004-10-13-12:00">INTERIM</status_change>
        <modified date="2004-10-19-04:29" comment="done">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2004-10-27-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
      <reference source="CVE">CVE-2002-0070</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-490" comment="the version of shell32.dll is less than 4.0.1381.7116" negate="false"/>
          <criterion test_ref="wrt-288" comment="Patch Q313829 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL19" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.</description>
      <reference source="CVE">CVE-2002-0189</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" negate="false"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL20" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2004-11-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-11-03-12:00">DRAFT</status_change>
        <status_change date="2004-12-09-12:00">INTERIM</status_change>
        <status_change date="2005-01-06-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
      <reference source="CVE">CVE-2003-0715</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-568" comment="the version of rpcss.dll is less than 5.0.2195.6810" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL22" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
      <reference source="CVE">CVE-2002-0147</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL23" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
      <reference source="CVE">CVE-2002-0026</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL24" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>FTP</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
      <reference source="CVE">CVE-2002-0073</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-202" comment="FTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL25" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
      <reference source="CVE">CVE-2002-0079</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL26" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Network Connection Manager (NCM)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.</description>
      <reference source="CVE">CVE-2002-0720</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
          <criterion test_ref="wft-207" comment="the version of netman.dll is less than 5.0.2195.5974" negate="false"/>
          <criterion test_ref="wrt-229" comment="Patch Q326886 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL27" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.01</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.</description>
      <reference source="CVE">CVE-2002-0193</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" negate="false"/>
          <criterion test_ref="wft-208" comment="the version of mshtml.dll is less than 5.0.3504.2500" negate="false"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="cmp-215" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL28" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>skk</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2003-0539</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-216" comment="Vulnerable config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL29" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."</description>
      <reference source="CVE">CVE-2002-0364</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-209" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" negate="false"/>
          <criterion test_ref="wrt-238" comment="Patch Q321599 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-203" comment="ism.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL30" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SMTP</product>
      </affected>
      <dates>
        <submitted date="2003-05-20-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-30-12:00" comment="Changed the registry key in question for the SMTP enabled check to SMTPSVC from SMTP.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
      </dates>
      <description>SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 to cause a denial of service via a command with a malformed data transfer (BDAT) request.</description>
      <reference source="CVE">CVE-2002-0055</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-210" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" negate="false"/>
          <criterion test_ref="wrt-239" comment="Patch Q313450" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-240" comment="SMTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL31" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to include Solaris 9 and Solaris 9 patch info">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:24">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-207" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL32" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
      <reference source="CVE">CVE-2002-0026</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL33" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-208" comment="Patch 108376-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL34" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-209" comment="Patch 111600-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL35" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>FTP</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
      <reference source="CVE">CVE-2002-0073</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-202" comment="FTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL37" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
      <reference source="CVE">CVE-2001-0333</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-211" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" negate="false"/>
          <criterion test_ref="wrt-241" comment="Patch Q295534 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-243" comment="Windows NT 4.0 Security Roll-up Package" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL38" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-05-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-09-26-10:55" comment="modified wft-212 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.</description>
      <reference source="CVE">CVE-2002-0051</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" negate="false"/>
          <criterion test_ref="wft-212" comment="the version of srvsvc.dll is less than 5.0.2195.4980" negate="false"/>
          <criterion test_ref="wrt-246" comment="Patch Q318593 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL39" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
      <reference source="CVE">CVE-2002-0150</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL40" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
      <reference source="CVE">CVE-2002-0023</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL41" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-210" comment="Patch 112899-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL42" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-02-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-223" comment="Patches 106942-22 and 108451-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL43" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:25">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL44" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.</description>
      <reference source="CVE">CVE-2000-0884</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-213" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" negate="false"/>
          <criterion test_ref="wrt-247" comment="Patch Q269862 Installed" negate="true"/>
          <criterion test_ref="wrt-248" comment="Patch Q277873 Installed" negate="true"/>
          <criterion test_ref="wrt-249" comment="Patch Q293826 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL45" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
      <reference source="CVE">CVE-2002-0071</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-203" comment="ism.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL46" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.</description>
      <reference source="CVE">CVE-2002-0074</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL47" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-213" comment="Patch 111826-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL48" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL49" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.01</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
      <reference source="CVE">CVE-2003-1326</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-230" comment="Internet Explorer 5.01 Installed" negate="false"/>
          <criterion test_ref="wft-214" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" negate="false"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-252" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL50" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1, or Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
      <reference source="CVE">CVE-2002-0023</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" negate="false"/>
          <criterion test_ref="wft-215" comment="the version of mshtml.dll is less than 5.0.3502.4856" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL52" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>EOG</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</description>
      <reference source="CVE">CVE-2003-0165</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-205" comment="eog version is less than 2.2.0-2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-232" comment="eog is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL54" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</description>
      <reference source="CVE">CVE-2003-0081</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL55" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0159</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL56" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-214" comment="Patch 111596-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL57" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."</description>
      <reference source="CVE">CVE-2003-1328</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" negate="false"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL58" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-08-20-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.</description>
      <reference source="CVE">CVE-2002-0075</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL59" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.</description>
      <reference source="CVE">CVE-2002-1561</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-217" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" negate="false"/>
          <criterion test_ref="wrt-253" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" negate="true"/>
          <criterion test_ref="wrt-254" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL60" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL61" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Remote Access Service (RAS)</product>
      </affected>
      <dates>
        <submitted date="2003-04-04-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
      <reference source="CVE">CVE-2002-0366</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wrt-256" comment="RAS Phonebook" negate="false"/>
          <criterion test_ref="wft-218" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" negate="false"/>
          <criterion test_ref="wrt-257" comment="Patch Q318138 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-258" comment="RAS Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL62" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL63" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Access Service (RAS)</product>
      </affected>
      <dates>
        <submitted date="2003-04-04-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
      <reference source="CVE">CVE-2002-0366</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-256" comment="RAS Phonebook" negate="false"/>
          <criterion test_ref="wft-219" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" negate="false"/>
          <criterion test_ref="wrt-257" comment="Patch Q318138 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-258" comment="RAS Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL64" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-05-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-08-04-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <status_change date="2004-08-26-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:56" comment="modified wft-220 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
      <reference source="CVE">CVE-2002-0018</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-220" comment="File %windir%\system32\netlogon.dll version is less than 5.0.893.1105" negate="false"/>
          <criterion test_ref="wrt-259" comment="Windows 2000 Security Roll-up 1 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL65" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
          <criterion test_ref="spt-216" comment="Patch 107337-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL66" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</description>
      <reference source="CVE">CVE-2003-0223</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" negate="false"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL67" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-217" comment="Patch 110453-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL68" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-218" comment="Patch 108721-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL69" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</description>
      <reference source="CVE">CVE-2003-0356</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL70" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-219" comment="Patch 108949-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL71" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-06-24-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-04-07-12:00" comment="modified wft-222 - corrected literal component of file path. It was missing the leading '\'">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <modified date="2005-04-07-09:25" comment="modified wft-222 - Corrected comment">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</description>
      <reference source="CVE">CVE-2001-0344</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-222" comment="the version of sqlservr.exe is less than 2000.80.296.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-261" comment="Mixed Mode Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL72" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
      <reference source="CVE">CVE-2002-0147</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL73" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</description>
      <reference source="CVE">CVE-2003-0357</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL74" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-220" comment="Patch 106934-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL75" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</description>
      <reference source="CVE">CVE-2003-0428</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL76" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-04-04-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
      <reference source="CVE">CVE-2002-0367</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-223" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" negate="false"/>
          <criterion test_ref="wrt-262" comment="Patch Q320206 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL77" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
      <reference source="CVE">CVE-2002-0023</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL78" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-08-04-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <status_change date="2004-08-26-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
      <reference source="CVE">CVE-2001-0333</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-224" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" negate="false"/>
          <criterion test_ref="wrt-249" comment="Patch Q293826 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-259" comment="Windows 2000 Security Roll-up 1 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL79" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-221" comment="Patch 112846-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL80" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL81" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-08-20-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
      <reference source="CVE">CVE-2002-0148</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL82" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-08-27-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-04-07-12:00" comment="modified wft-225 - correct literal component in file path. Added '\' to the start of the literal string.">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-04-11-12:00">INTERIM</status_change>
        <modified date="2005-04-12-12:00" comment="modified wft-89 - wft-89 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-27-01:26" comment="modified wft-89 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</description>
      <reference source="CVE">CVE-2001-0509</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-225" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" negate="false"/>
          <criterion test_ref="wft-59" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" negate="false"/>
          <criterion test_ref="wft-89" comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL83" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-04-08-12:00" comment="modified wft-227 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-26-10:57" comment="modified wft-227 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.</description>
      <reference source="CVE">CVE-2001-0542</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-227" comment="File sqlservr.exe version3 less than 2000.80.428.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL84" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2003-0429</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL86" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-223" comment="Patch 108652-51 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL87" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Simple Network Management Protocol (SNMP)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
      </dates>
      <description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0013</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" negate="false"/>
          <criterion test_ref="wrt-263" comment="Patch Q314147 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL88" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</description>
      <reference source="CVE">CVE-2003-0430</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" ne